First published: Mon Feb 12 2024(Updated: )
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
Credit: cve-coordination@incibe.es cve-coordination@incibe.es
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | <=4.2.0 | |
Moodle | <=4.2.11 |
There is no reported solution at this time.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-1439 has been classified with a moderate severity due to its potential for unauthorized event creation.
To fix CVE-2024-1439, update Moodle to version 4.2.1 or later, which addresses the inadequate access control issue.
CVE-2024-1439 affects local users with a student role in Moodle versions up to and including 4.2.0.
An attacker can create arbitrary events intended for users with higher roles and add events to the calendars of all users.
Yes, a patch is available in the updated Moodle versions that resolve the vulnerabilities related to CVE-2024-1439.