CVE-2012-6106

Moodle 2.4.x - Authenticated Calendar Subscription Removal via managesubscriptions.php

Title source: llm
STIX 2.1

Description

calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=220167
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2013/01/21/1

Scores

EPSS 0.0044
EPSS Percentile 63.4%

Details

CWE
CWE-264
Status published
Products (1)
moodle/moodle 2.4.0
Published Jan 27, 2013
Tracked Since Feb 18, 2026