CVE-2019-14883

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
18/03/2020
Last modified:
09/10/2020

Description

A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.6.0 (including) 3.6.7 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.7.0 (including) 3.7.3 (excluding)