Moodle Permissions Privileges and Access Controls Vulnerability - CVE-2012-2367 - Vulnerability Database

Moodle Permissions Privileges and Access Controls Vulnerability - CVE-2012-2367

Medium
Reference: CVE-2012-2367
Title: Moodle Permissions Privileges and Access Controls Vulnerability
Overview:

Moodle 1.9.x before 1.9.18 2.0.x before 2.0.9 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.