CVE-2022-0333

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/01/2022
Last modified:
21/12/2022

Description

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The calendar:manageentries capability allowed managers to access or modify any calendar event, but should have been restricted from accessing user level events.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.8.9 (including)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.9.0 (including) 3.9.12 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.10.0 (including) 3.10.9 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.11.0 (including) 3.11.5 (excluding)