Description
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.
Remediation
References
Related Vulnerabilities
WordPress Plugin WP Hotel Booking SQL Injection (2.1.0)
MySQL CVE-2020-14654 Vulnerability (CVE-2020-14654)
WordPress Plugin Border Loading Bar Multiple Cross-Site Scripting Vulnerabilities (1.0)
WordPress Plugin AnnounceME Cross-Site Scripting (0.3.3)
Magento Incorrect Authorization Vulnerability (CVE-2020-9692)