CVE-2019-3848
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
26/03/2019
Last modified:
07/11/2022
Description
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
Impact
Base Score 3.x
4.30
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.4.8 (excluding) | |
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.5.0 (including) | 3.5.5 (excluding) |
| cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | 3.6.0 (including) | 3.6.3 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



