Vulnerability Name: | CVE-2019-3849 (CCN-159479) | ||||||||||||||||||||||||||||||||
Assigned: | 2019-03-19 | ||||||||||||||||||||||||||||||||
Published: | 2019-03-19 | ||||||||||||||||||||||||||||||||
Updated: | 2020-10-16 | ||||||||||||||||||||||||||||||||
Summary: | A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site. | ||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 8.8 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) 7.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
5.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)
| ||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-269 CWE-285 | ||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2019-3849 Source: CONFIRM Type: Issue Tracking, Patch, Third Party Advisory https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 Source: XF Type: UNKNOWN moodle-cve20193849-priv-esc(159479) Source: CCN Type: Moodle Security Advisory MSA-19-0006 Users could elevate their role when accessing the LTI tool on a provider site Source: MISC Type: Patch, Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 | ||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||
BACK |