{"api_version":"1","generated_at":"2026-07-23T12:59:13+00:00","cve":"CVE-2019-3809","urls":{"html":"https://cve.report/CVE-2019-3809","api":"https://cve.report/api/cve/CVE-2019-3809.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-3809","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-3809"},"summary":{"title":"CVE-2019-3809","description":"A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.","state":"PUBLIC","assigner":"secalert@redhat.com","published_at":"2019-03-25 18:29:00","updated_at":"2019-10-09 23:49:00"},"problem_types":["CWE-918"],"metrics":[],"references":[{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222","name":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Official Moodle git projects - moodle.git/search","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3809","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3809","refsource":"CONFIRM","tags":["Issue Tracking","Patch","Third Party Advisory"],"title":"1668067 – (CVE-2019-3809) CVE-2019-3809 moodle: Blind SSRF Risk in /badges/mybackpack.php (MSA-19-0002)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://moodle.org/mod/forum/discuss.php?d=381229#p1536766","name":"https://moodle.org/mod/forum/discuss.php?d=381229#p1536766","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"Moodle.org: MSA-19-0002: Blind SSRF Risk in /badges/mybackpack.php","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-3809","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-3809","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"3809","vulnerable":"1","versionEndIncluding":"3.1.15","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moodle","cpe5":"moodle","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-3809","ASSIGNER":"secalert@redhat.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"[UNKNOWN]","product":{"product_data":[{"product_name":"moodle","version":{"version_data":[{"version_value":"3.1.16"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"CWE-352"}]}]},"references":{"reference_data":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3809","name":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3809","refsource":"CONFIRM"},{"url":"https://moodle.org/mod/forum/discuss.php?d=381229#p1536766","name":"https://moodle.org/mod/forum/discuss.php?d=381229#p1536766","refsource":"CONFIRM"},{"url":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222","name":"http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222","refsource":"CONFIRM"}]},"description":{"description_data":[{"lang":"eng","value":"A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page."}]},"impact":{"cvss":[[{"vectorString":"6.5/CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","version":"3.0"}]]}},"nvd":{"publishedDate":"2019-03-25 18:29:00","lastModifiedDate":"2019-10-09 23:49:00","problem_types":["CWE-918"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":10,"baseSeverity":"CRITICAL"},"exploitabilityScore":3.9,"impactScore":6},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","versionStartIncluding":"3.1.0","versionEndIncluding":"3.1.15","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"3809","Ordinal":"141418","Title":"CVE-2019-3809","CVE":"CVE-2019-3809","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"3809","Ordinal":"1","NoteData":"A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"3809","Ordinal":"2","NoteData":"2019-03-25","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"3809","Ordinal":"3","NoteData":"2019-03-25","Type":"Other","Title":"Modified"}]}}}