CVE-2019-10134 Information

Description

A flaw was found in Moodle before 3.7 3.6.4 3.5.6 3.4.9 and 3.1.18. The size of users’ private file uploads via email were not correctly checked so their quota allowance could be exceeded.

CVSS Vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Reference

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10134 https://moodle.org/mod/forum/discuss.php?d=386524

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

NONE

Availability Impact

LOW

Base Score

NONE

Base Severity

3.7

Share on: