PT-2019-16744 · Moodle · Moodle

Steeven George

·

Publicado

2019-03-26

·

Atualizado

2022-05-13

·

CVE-2019-3850

CVSS v3.1

6.1

Média

VetorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions moodle versions prior to 3.6.3 moodle versions prior to 3.5.5 moodle versions prior to 3.4.8 moodle versions prior to 3.1.17
Description A vulnerability was found where links within assignment submission comments would open directly in the same window, making them more susceptible to exploits due to the lack of the no-referrer header policy.
Recommendations For versions prior to 3.6.3, update to version 3.6.3 or later. For versions prior to 3.5.5, update to version 3.5.5 or later. For versions prior to 3.4.8, update to version 3.4.8 or later. For versions prior to 3.1.17, update to version 3.1.17 or later.

Correção

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-3850
GHSA-3FJ7-9J8M-7R8G

Produtos afetados

Moodle