CVE-2013-1829

Publication date

2013-03-25 21:00:00

Family

redhat

State

PUBLISHED

Description

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.