PT-2020-9622 · Moodle+1 · Moodle+1
Juan Leyva
·
Published
2019-11-16
·
Updated
2022-05-24
·
CVE-2019-14883
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle versions 3.6 through 3.6.6
Moodle versions 3.7 through 3.7.2
Description
A vulnerability was found where tokens used to fetch inline attachments in email notifications were not disabled when a user's account was no longer active. To access files, a user would need to know the file path and their token.
Recommendations
For Moodle versions 3.6 through 3.6.6, update to version 3.6.7 or later.
For Moodle versions 3.7 through 3.7.2, update to version 3.7.3 or later.
As a temporary workaround, consider restricting access to email notifications and inline attachments for inactive user accounts until a patch is available.
Fix
Improper Authorization
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Moodle