CVE-2019-10133 PUBLISHED

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

EPSS 0.16% · 37.4th percentile

Risk Scores

EPSS Score
0.16%
37.4th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSmoodle0, 3.0.3+dfsg-0ubuntu1
Ubuntu:16.04:LTSmoodle2.7.10+dfsg-1, 2.7.11+dfsg-1, 0

Timeline

References

Open in Interactive Console →