A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
References
Link | Resource |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3849 | Issue Tracking Patch Third Party Advisory |
https://moodle.org/mod/forum/discuss.php?d=384012#p1547744 | Patch Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2019-03-26T17:46:47
Updated: 2019-03-26T17:46:47
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3849
JSON object: View
NVD Information
Status : Analyzed
Published: 2019-03-26T18:29:00.780
Modified: 2020-10-16T18:48:23.820
Link: CVE-2019-3849
JSON object: View
Redhat Information
No data.