What the vulnerability does

01Description

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. Insufficient capability checks made it possible to fetch other users' calendar action events.

Key dates

02Disclosure timeline

November 22, 2021 CVE published
August 4, 2024 Record updated