A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
References
Link | Resource |
---|---|
https://moodle.org/mod/forum/discuss.php?d=381228#p1536765 | Patch Vendor Advisory |
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3808 | Issue Tracking Patch Third Party Advisory |
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2019-03-25 11:29
Updated : 2020-10-19 11:03
NVD link : CVE-2019-3808
Mitre link : CVE-2019-3808
JSON object : View
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Products Affected
moodle
- moodle