VDB
CVE-2019-14827
CVE-2019-14827
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that context was injected into another Mustache helper, which could result in script injection in some templates. This affects versions 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions.
EPSS 0.67% · 49.2th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.67%
49.2th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | moodle | 0, * |
| Ubuntu:16.04:LTS | moodle | 0, 2.7.9+dfsg-1, 2.7.11+dfsg-2 |
Timeline
- Sep 16, 2019 CVE Published
- May 18, 2021 EPSS Score
- Jul 21, 2021 EPSS Score
- Sep 21, 2021 EPSS Score
- Nov 21, 2021 EPSS Score
- Jan 22, 2022 EPSS Score
- May 26, 2022 EPSS Score
- Jul 28, 2022 EPSS Score
- Sep 27, 2022 EPSS Score
- Nov 28, 2022 EPSS Score
- Jan 29, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-14827 third-party-advisory
- https://moodle.org/mod/forum/discuss.php?d=391030 third-party-advisory
- https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-62284 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14827 third-party-advisory