CVE-2019-3808
Description
A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default.
CWE
- CWE-79 — CWE-79
Affected
- [UNKNOWN] / moodle — v=3.6.2 [affected]; v=3.5.4 [affected]; v=3.4.7 [affected]; v=3.1.16 [affected]
CVSS
- 3.0 score=4.3 severity=MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
References
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3808 x_refsource_CONFIRM
- https://moodle.org/mod/forum/discuss.php?d=381228#p1536765 x_refsource_CONFIRM
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64395 x_refsource_CONFIRM
Source
cvelistV5-main/cves/2019/3xxx/CVE-2019-3808.json