CVE-2024-1439 Vulnerability Details

  /     /     /  

CVE-2024-1439 Metadata Quick Info

CVE Published: 12/02/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: INCIBE | Vendor: Moodle | Product: LMS
Status : PUBLISHED

CVE-2024-1439 Description

Inadequate access control in Moodle LMS. This vulnerability could allow a local user with a student role to create arbitrary events intended for users with higher roles. It could also allow the attacker to add events to the calendar of all users without their prior consent.

Metrics

CVSS Version: 3.1 | Base Score: 6.5 MEDIUM
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* LOW
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* HIGH
    Availability Impact (A)* NONE

Weakness Enumeration (CWE)

CWE-ID: CWE-284
CWE Name: CWE-284 Improper Access Control
Source: Moodle

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-536
CAPEC Description: CAPEC-536 Data Injected During Configuration


Source: NVD (National Vulnerability Database).