VulnerabilityModified
CVE-2019-10134
The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
LOW 3.7EPSS 1.05%
Does this matter?
Lower severity and a low EPSS score (1.05%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
- CVSS 3.1
- 3.7 LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.05% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134Issue Tracking, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=386524Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134Issue Tracking, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=386524Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.