VulnerabilityModified
CVE-2019-3810
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions.
MEDIUM 6.1EPSS 13.9%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 13.9%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
- CVSS 3.1
- 6.1 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 13.90% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64372Patch, Vendor Advisory
- http://packetstormsecurity.com/files/162399/Moodle-3.6.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3810Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=381230#p1536767Patch, Vendor Advisory
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64372Patch, Vendor Advisory
- http://packetstormsecurity.com/files/162399/Moodle-3.6.1-Cross-Site-Scripting.htmlExploit, Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3810Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=381230#p1536767Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.