VYPR
Unrated severityNVD Advisory· Published Mar 25, 2013· Updated Apr 29, 2026

CVE-2013-1829

CVE-2013-1829

Description

calendar/managesubscriptions.php in Moodle 2.4.x before 2.4.2 does not consider capability requirements before displaying calendar subscriptions, which allows remote authenticated users to obtain potentially sensitive information by leveraging the student role.

Affected products

2
  • Moodle/Moodle2 versions
    cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:moodle:moodle:2.4.0:*:*:*:*:*:*:*
    • cpe:2.3:a:moodle:moodle:2.4.1:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.