A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:42
Type | Values Removed | Values Added |
---|---|---|
References | () https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 - Issue Tracking, Patch, Third Party Advisory | |
References | () https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 - Patch, Vendor Advisory |
Information
Published : 2019-03-26 18:29
Updated : 2024-11-21 04:42
NVD link : CVE-2019-3849
Mitre link : CVE-2019-3849
CVE.ORG link : CVE-2019-3849
JSON object : View
Products Affected
moodle
- moodle