← Zuruck zu CVEs
CVE-2019-3848
MEDIUM4.3
Beschreibung
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
CVE Details
CVSS v3.1 Bewertung4.3
SchweregradMEDIUM
CVSS VektorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
AngriffsvektorNETWORK
KomplexitatLOW
Erforderliche PrivilegienLOW
BenutzerinteraktionNONE
Veroffentlicht3/26/2019
Zuletzt geandert11/21/2024
Quellenvd
Honeypot-Sichtungen0
Betroffene Produkte
moodle:moodle
Schwachen (CWE)
CWE-863CWE-863
Referenzen
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3848(secalert@redhat.com)
https://moodle.org/mod/forum/discuss.php?d=384011#p1547743(secalert@redhat.com)
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3848(af854a3a-2127-422b-91ae-364da2661108)
https://moodle.org/mod/forum/discuss.php?d=384011#p1547743(af854a3a-2127-422b-91ae-364da2661108)
IOC Korrelationen
Keine Korrelationen erfasst
This product uses data from the NVD API but is not endorsed or certified by the NVD.