CVE-2024-33996
31.05.2024, 20:15
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.Enginsight
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 𝑥 < 4.1.10 |
| moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.7 |
| moodle | moodle | 4.3.0 ≤ 𝑥 < 4.3.4 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration