PT-2020-9622 · Moodle+1 · Moodle+1

Juan Leyva

·

Published

2019-11-16

·

Updated

2022-05-24

·

CVE-2019-14883

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions 3.6 through 3.6.6 Moodle versions 3.7 through 3.7.2
Description A vulnerability was found where tokens used to fetch inline attachments in email notifications were not disabled when a user's account was no longer active. To access files, a user would need to know the file path and their token.
Recommendations For Moodle versions 3.6 through 3.6.6, update to version 3.6.7 or later. For Moodle versions 3.7 through 3.7.2, update to version 3.7.3 or later. As a temporary workaround, consider restricting access to email notifications and inline attachments for inactive user accounts until a patch is available.

Fix

Improper Authorization

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-3145
ALT-PU-2020-1250
CVE-2019-14883
GHSA-774Q-WFCP-VC2Q

Affected Products

Alt Linux
Moodle