VDB
CVE-2019-14831
CVE-2019-14831
PUBLISHED
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.
EPSS 0.19% · 41.0th percentile
Risk Scores
EPSS Score
0.19%
41.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:18.04:LTS | moodle | 0, 3.0.3+dfsg-0ubuntu1 |
| Ubuntu:16.04:LTS | moodle | 0, 2.7.9+dfsg-1, 2.7.11+dfsg-1 |
Timeline
- Sep 16, 2019 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 1, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Nov 6, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2019-14831 third-party-advisory
- https://git.moodle.org/gw?p=moodle.git;a=commit;h=32e2e06a8737afb07ee83abb3eacd39f8b181216 third-party-advisory
- https://moodle.org/mod/forum/discuss.php?d=391037 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2019-14831 third-party-advisory