CVE-2012-6106
Publication date 27 January 2013
Last updated 24 July 2024
Ubuntu priority
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.
Status
Package | Ubuntu Release | Status |
---|---|---|
moodle | ||
Patch details
Package | Patch details |
---|---|
moodle |