Description
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a web-services request.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2015-4873 Vulnerability (CVE-2015-4873)
WebLogic CVE-2018-3252 Vulnerability (CVE-2018-3252)
Moodle Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3545)
MySQL CVE-2024-21087 Vulnerability (CVE-2024-21087)
SharePoint Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-2816)