CVE-2024-33996
31.05.2024, 20:15
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 4.1.10 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.7 |
moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration