{"api_version":"1","generated_at":"2026-07-23T09:39:18+00:00","cve":"CVE-2019-14829","urls":{"html":"https://cve.report/CVE-2019-14829","api":"https://cve.report/api/cve/CVE-2019-14829.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-14829","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-14829"},"summary":{"title":"CVE-2019-14829","description":"A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2021-03-19 21:15:00","updated_at":"2023-02-12 23:34:00"},"problem_types":["CWE-573"],"metrics":[],"references":[{"url":"https://moodle.org/mod/forum/discuss.php?d=391035","name":"https://moodle.org/mod/forum/discuss.php?d=391035","refsource":"MISC","tags":[],"title":"Moodle.org: MSA-19-0021: Activity :addinstance capabilities were not respected when creating a course in single activity format","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=208397c120b6bf74ca6a173e42cb527904c5ab42","name":"https://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=208397c120b6bf74ca6a173e42cb527904c5ab42","refsource":"MISC","tags":[],"title":"Official Moodle git projects - moodle.git/commit","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"https://git.moodle.org/gw?p=moodle.git;a=commit;h=208397c120b6bf74ca6a173e42cb527904c5ab42","name":"https://git.moodle.org/gw?p=moodle.git;a=commit;h=208397c120b6bf74ca6a173e42cb527904c5ab42","refsource":"MISC","tags":[],"title":"Official Moodle git projects - moodle.git/commit","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-14829","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14829","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"14829","vulnerable":"1","versionEndIncluding":"3.5.7","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"14829","vulnerable":"1","versionEndIncluding":"3.6.5","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"14829","vulnerable":"1","versionEndIncluding":"3.7.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_version":"4.0","data_type":"CVE","data_format":"MITRE","CVE_data_meta":{"ID":"CVE-2019-14829","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"description":{"description_data":[{"lang":"eng","value":"A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-573","cweId":"CWE-573"}]}]},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Moodle","version":{"version_data":[{"version_affected":"=","version_value":"3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions"}]}}]}}]}},"references":{"reference_data":[{"url":"https://moodle.org/mod/forum/discuss.php?d=391035","refsource":"MISC","name":"https://moodle.org/mod/forum/discuss.php?d=391035"},{"url":"https://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=208397c120b6bf74ca6a173e42cb527904c5ab42","refsource":"MISC","name":"https://git.moodle.org/gw?p=moodle.git%3Ba=commit%3Bh=208397c120b6bf74ca6a173e42cb527904c5ab42"}]}},"nvd":{"publishedDate":"2021-03-19 21:15:00","lastModifiedDate":"2023-02-12 23:34:00","problem_types":["CWE-573"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":4.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":2.8,"impactScore":1.4},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4},"severity":"MEDIUM","exploitabilityScore":8,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.5.0","versionEndIncluding":"3.5.7","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.6.0","versionEndIncluding":"3.6.5","cpe_name":[]},{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.7.0","versionEndIncluding":"3.7.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"14829","Ordinal":"154038","Title":"CVE-2019-14829","CVE":"CVE-2019-14829","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"14829","Ordinal":"1","NoteData":"A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"14829","Ordinal":"2","NoteData":"2021-03-19","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"14829","Ordinal":"3","NoteData":"2021-03-19","Type":"Other","Title":"Modified"}]}}}