Moodle provides calendar-event data without considering whether an activity is hidden
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 26, 2024
Package
Affected versions
< 2.7.13
>= 2.8.0, < 2.8.11
>= 2.9.0, < 2.9.5
>= 3.0.0, < 3.0.3
Patched versions
2.7.13
2.8.11
2.9.5
3.0.3
Description
Published by the National Vulnerability Database
May 22, 2016
Published to the GitHub Advisory Database
May 13, 2022
Last updated
Jan 26, 2024
Reviewed
Jan 26, 2024
calendar/externallib.php in Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 provides calendar-event data without considering whether an activity is hidden, which allows remote authenticated users to obtain sensitive information via a web-service request.
References