VDB
CVE-2019-10134
CVE-2019-10134
PUBLISHED
CVSS 4.199999809265137 MEDIUM
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
EPSS 1.05% · 63.1th percentile
Risk Scores
CVSS 3.0
4.199999809265137
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS Score
1.05%
63.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | moodle | 0, 3.0.3+dfsg-0ubuntu1 |
| Ubuntu:16.04:LTS | moodle | 2.7.9+dfsg-1, 2.7.10+dfsg-1, 2.7.11+dfsg-1 |
Timeline
- May 21, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Dec 29, 2021 EPSS Score
- Jan 6, 2022 EPSS Score
- Feb 4, 2022 EPSS Score
- Mar 2, 2022 EPSS Score
- Apr 1, 2022 EPSS Score
- May 4, 2022 EPSS Score
- Sep 9, 2022 EPSS Score
- Nov 11, 2022 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-10134 third-party-advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134 third-party-advisory
- https://moodle.org/mod/forum/discuss.php?d=386524 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-10134 third-party-advisory