VDB
CVE-2019-14831
CVE-2019-14831
PUBLISHED
CVSS 6.099999904632568 MEDIUM
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.
EPSS 0.81% · 54.1th percentile
Risk Scores
CVSS 3.1
6.099999904632568
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
EPSS Score
0.81%
54.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | moodle | 0, 3.0.3+dfsg-0ubuntu1 |
| Ubuntu:16.04:LTS | moodle | 0, 2.7.9+dfsg-1, 2.7.11+dfsg-1 |
Timeline
- Sep 16, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 25, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 28, 2021 EPSS Score
- Mar 1, 2022 EPSS Score
- May 3, 2022 EPSS Score
- Jul 5, 2022 EPSS Score
- Nov 8, 2022 EPSS Score
- Jan 10, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-14831 third-party-advisory
- https://git.moodle.org/gw?p=moodle.git;a=commit;h=32e2e06a8737afb07ee83abb3eacd39f8b181216 third-party-advisory
- https://moodle.org/mod/forum/discuss.php?d=391037 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14831 third-party-advisory