Security restrictions bypass in Moodle - CVE-2019-3810
Published: February 1, 2019 / Updated: June 17, 2021
Vulnerability details
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to the /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. A remote attacker can bypass security restrictions to conduct further attacks.
Affected software
Fedora
moodle
How to mitigate CVE-2019-3810
moodle - addressed in versions 3.1.16-1.el7, 3.4.7-1.fc28, 3.5.4-1.fc29