Description
Incorrect validation of allowed event types in a calendar web service made it possible for some users to create events with types/audiences they did not have permission to publish to.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4qww-rxq6-x7gf | Moodle broken access control when setting calendar event type |
References
| Link | Providers |
|---|---|
| https://moodle.org/mod/forum/discuss.php?d=458384#p1840909 |
|
History
Fri, 30 May 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-02T02:42:59.873Z
Reserved: 2024-04-29T13:02:30.265Z
Link: CVE-2024-33996
Updated: 2024-08-02T02:42:59.873Z
Status : Analyzed
Published: 2024-05-31T20:15:09.647
Modified: 2025-05-30T16:41:36.053
Link: CVE-2024-33996
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA