PT-2013-1896 · Moodle · Moodle

David Obrien

·

Published

2013-01-27

·

Updated

2020-12-01

·

CVE-2012-6106

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions 2.4.0
Description The issue is related to the Manage Subscriptions implementation in Moodle, where a capability check is omitted. This allows remote authenticated users with the student role to remove course-level calendar subscriptions by sending an iCalendar object.
Recommendations For Moodle version 2.4.0, update to version 2.4.1 to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-6106

Affected Products

Moodle