Description
calendar/managesubscriptions.php in the Manage Subscriptions implementation in Moodle 2.4.x before 2.4.1 omits a capability check, which allows remote authenticated users to remove course-level calendar subscriptions by leveraging the student role and sending an iCalendar object.
Remediation
References
Related Vulnerabilities
WordPress Other Vulnerability (CVE-2005-2108)
WordPress Plugin Appointments Unspecified Vulnerability (2.2.2.1)
Drupal Core 5.x SQL Injection (5.0 - 5.14)
PHP Improper Input Validation Vulnerability (CVE-2016-3185)
WordPress Plugin All-in-One Custom Backgrounds Lite Unspecified Vulnerability (2.0.2)