Vulnonym.com

CVE-2012-2367 - Dyable Ramp

Description

Moodle 1.9.x before 1.9.18 2.0.x before 2.0.9 2.1.x before 2.1.6 and 2.2.x before 2.2.3 allows remote authenticated users to bypass the moodle/calendar:manageownentries capability requirement and add a calendar entry via a New Entry action.

Reference

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-18335 http://openwall.com/lists/oss-security/2012/05/23/2 https://moodle.org/mod/forum/discuss.php?d=203057 http://www.securityfocus.com/bid/53626 http://osvdb.org/82074