CVE-2021-36400
06.03.2023, 22:15
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 3.9.8 |
moodle | moodle | 3.10.0 ≤ 𝑥 < 3.10.5 |
moodle | moodle | 3.11.0 ≤ 𝑥 < 3.11.1 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
- CWE-639 - Authorization Bypass Through User-Controlled KeyThe system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.