CVE-2024-33996: moodle: broken access control when setting calendar event type
Published May 31, 2024
·Updated
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle<4.1.10
4.1.10
composer/moodle/moodle>=4.2.0<4.2.7
4.2.7
composer/moodle/moodle>=4.3.0<4.3.4
4.3.4
Moodle moodle<4.1.10
Moodle moodle>=4.2.0<4.2.7
Moodle moodle>=4.3.0<4.3.4
Event History
May 31, 2024
CVE Published
via MITRE·07:29 PM
Data Sourced
via MITRE·07:29 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-33996?
CVE-2024-33996 has a moderate severity due to incorrect validation allowing unauthorized event type creation.
2
How do I fix CVE-2024-33996?
To fix CVE-2024-33996, update Moodle to version 4.1.10, 4.2.7, or 4.3.4 as recommended.
3
Which versions of Moodle are affected by CVE-2024-33996?
CVE-2024-33996 affects Moodle versions up to 4.1.10 and between 4.2.0 and 4.2.7, as well as 4.3.0 to 4.3.4.
4
What type of vulnerability is CVE-2024-33996?
CVE-2024-33996 is a vulnerability related to improper validation of event types in a calendar service.
5
Can CVE-2024-33996 lead to unauthorized access?
Yes, CVE-2024-33996 can lead to unauthorized users creating events they do not have permission to publish.