A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
References
Link | Resource |
---|---|
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3808 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=381228#p1536765 | Patch Vendor Advisory |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3808 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=381228#p1536765 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:42
Type | Values Removed | Values Added |
---|---|---|
References | () http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 - Patch, Vendor Advisory | |
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3808 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://moodle.org/mod/forum/discuss.php?d=381228#p1536765 - Patch, Vendor Advisory |
Information
Published : 2019-03-25 18:29
Updated : 2024-11-21 04:42
NVD link : CVE-2019-3808
Mitre link : CVE-2019-3808
CVE.ORG link : CVE-2019-3808
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')