CVE-2019-10134
Summary
| CVE | CVE-2019-10134 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-06-26 19:15:00 UTC |
| Updated | 2021-10-28 12:20:00 UTC |
| Description | A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Moodle.org: MSA-19-0012: Private files uploaded via incoming mail processing could bypass quota restrictions | CONFIRM | moodle.org | Patch, Vendor Advisory |
| 1716610 – (CVE-2019-10134) CVE-2019-10134 moodle: Private files uploaded via incoming mail processing could bypass quota restrictions | CONFIRM | bugzilla.redhat.com | Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.