VDB
CVE-2019-14829
CVE-2019-14829
PUBLISHED
CVSS 4.300000190734863 MEDIUM
A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.
EPSS 0.74% · 52.0th percentile
Risk Scores
CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
EPSS Score
0.74%
52.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | moodle | 0, 3.0.3+dfsg-0ubuntu1 |
| Ubuntu:16.04:LTS | moodle | 0, 2.7.9+dfsg-1, 2.7.10+dfsg-1 |
Timeline
- Sep 16, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-14829 third-party-advisory
- https://git.moodle.org/gw?p=moodle.git;a=commit;h=208397c120b6bf74ca6a173e42cb527904c5ab42 third-party-advisory
- https://moodle.org/mod/forum/discuss.php?d=391035 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14829 third-party-advisory