CVE-2019-3849 Information

Description

A vulnerability was found in moodle before versions 3.6.3 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI by modifying the request to the LTI publisher site.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Reference

https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 https://moodle.org/mod/forum/discuss.php?d=384012p1547744

Attack Complexity

LOW

Privileges Required

LOW

User Interaction Required

LOW

Scope

NONE

Confidentiality Impact

UNCHANGED

Integrity Impact

HIGH

Availability Impact

HIGH

Base Score

HIGH

Base Severity

8.8

Share on: