ALT-PU-2019-2080-2
Closed vulnerabilities
Published: 2019-06-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-10133
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Severity: MEDIUM (5.8)Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N
Severity: MEDIUM (6.1)Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
Published: 2019-06-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-10134
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
Severity: MEDIUM (4.3)Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
Severity: LOW (3.7)Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
References:
Published: 2019-06-26
Modified: 2024-11-21
Modified: 2024-11-21
CVE-2019-10154
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
Severity: MEDIUM (5.0)Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N
Severity: HIGH (7.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
Published: 2022-05-24
Modified: 2024-01-26
Modified: 2024-01-26
GHSA-5xp2-rv4h-mm2q
Moodle Open Redirect Vulnerability
Severity: MEDIUM (6.1)Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10133
- https://github.com/moodle/moodle/commit/5a89ac9640b3a695720845b6ddeff65e69a289fc
- https://github.com/moodle/moodle/commit/a6258d0934f707b1d033f50fb41ffbcf45bb2102
- https://github.com/moodle/moodle/commit/c509d108216524887c7ca08b1c451054d669ea75
- https://github.com/moodle/moodle/commit/cd6fb4322b6b1914c05f05033a71ed060f875fd4
- https://github.com/moodle/moodle/commit/d5067bffd230d733ad24f6aeaa56aaa17eca5bfb
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10133
- https://github.com/moodle/moodle
- https://moodle.org/mod/forum/discuss.php?d=386523
Published: 2022-05-24
Modified: 2024-04-24
Modified: 2024-04-24
GHSA-j8wr-7xxj-c2fr
Moodle Private files uploaded via incoming mail processing could bypass quota restrictions
Severity: MEDIUM (4.2)Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
References:
Published: 2022-05-24
Modified: 2024-01-26
Modified: 2024-01-26
GHSA-ww45-x87c-wgff
Moodle all messaging conversations could be viewed
Severity: HIGH (7.5)Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
References:
- https://nvd.nist.gov/vuln/detail/CVE-2019-10154
- https://github.com/moodle/moodle/commit/2904a7f851da8e66be12f41d55068bf07817fbd6
- https://github.com/moodle/moodle/commit/a3d19efab4aff83c07db9f0ad34c8f0e1f29c64c
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10154
- https://github.com/moodle/moodle
- https://moodle.org/mod/forum/discuss.php?d=386521
