CVE-2019-3808
Summary
| CVE | CVE-2019-3808 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-25 18:29:00 UTC |
| Updated | 2020-10-19 18:03:00 UTC |
| Description | A flaw was found in Moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The 'manage groups' capability did not have the 'XSS risk' flag assigned to it, but does have that access in certain places. Note that the capability is intended for use by trusted users, and is only assigned to teachers and managers by default. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Moodle | Moodle | 3.6.0 | All | All | All |
| Application | Moodle | Moodle | 3.6.1 | All | All | All |
| Application | Moodle | Moodle | 3.6.0 | All | All | All |
| Application | Moodle | Moodle | 3.6.1 | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
| Application | Moodle | Moodle | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 1668064 – (CVE-2019-3808) CVE-2019-3808 moodle: Manage groups capability is missing XSS risk flag (MSA-19-0001) | CONFIRM | bugzilla.redhat.com | Issue Tracking, Patch, Third Party Advisory |
| Moodle.org: MSA-19-0001: Manage groups capability is missing XSS risk flag | CONFIRM | moodle.org | Patch, Vendor Advisory |
| Official Moodle git projects - moodle.git/search | CONFIRM | git.moodle.org | Patch, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.