CVE-2019-14831 Information

Description

A vulnerability was found in Moodle 3.7 to 3.7.1 3.6 to 3.6.5 3.5 to 3.5.7 and earlier unsupported versions where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum’s subscription mode was set to orced subscription\ the forum’s subscribe link contained an open redirect.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://git.moodle.org/gw?p=moodle.git;a=commit;h=32e2e06a8737afb07ee83abb3eacd39f8b181216 https://moodle.org/mod/forum/discuss.php?d=391037

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: