CVE-2019-3808
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
25/03/2019
Last modified:
19/10/2020
Description
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.1.0 (including) | 3.1.15 (including) |
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.4.0 (including) | 3.4.6 (including) |
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.5.0 (including) | 3.5.3 (including) |
| cpe:2.3:a:moodle:moodle:3.6.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:moodle:moodle:3.6.1:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



