CVE-2019-14830 Information
Jun 07, 2022
cve
Description
A vulnerability was found in Moodle 3.7 to 3.7.1 3.6 to 3.6.5 3.5 to 3.5.7 and earlier unsupported versions where the mobile launch endpoint contained an open redirect in some circumstances which could result in a user’s mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured mobile service disabled or where the mobile app login method is ia the app).
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://git.moodle.org/gw?p=moodle.git;a=commit;h=d4985a77391123c5959db432c076328f8d5e3624 https://moodle.org/mod/forum/discuss.php?d=391036
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: