VulnerabilityModified
CVE-2019-3849
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8.
HIGH 8.8EPSS 1.02%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.02%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.02% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-285, CWE-269
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=384012#p1547744Patch, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849Issue Tracking, Patch, Third Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=384012#p1547744Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.