CVE-2024-1439: Inadequate access control vulnerability in Moodle
Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1439?
CVE-2024-1439 has been classified with a moderate severity due to its potential for unauthorized event creation.
How do I fix CVE-2024-1439?
To fix CVE-2024-1439, update Moodle to version 4.2.1 or later, which addresses the inadequate access control issue.
Who is affected by CVE-2024-1439?
CVE-2024-1439 affects local users with a student role in Moodle versions up to and including 4.2.0.
What types of attacks can be executed using CVE-2024-1439?
An attacker can create arbitrary events intended for users with higher roles and add events to the calendars of all users.
Is a patch available for CVE-2024-1439?
Yes, a patch is available in the updated Moodle versions that resolve the vulnerabilities related to CVE-2024-1439.