Headline
GHSA-35wf-3wq2-r3hx: Moodle has Incorrect Default Permissions
In Moodle, insufficient capability checks made it possible to remove other users’ calendar URL subscriptions.
Moodle has Incorrect Default Permissions
Moderate severity GitHub Reviewed Published Mar 7, 2023 to the GitHub Advisory Database • Updated Mar 8, 2023
Related news
CVE-2021-36400
In Moodle, insufficient capability checks made it possible to remove other users' calendar URL subscriptions.