#VU17355 Security restrictions bypass in Moodle


Published: 2021-06-17

Vulnerability identifier: #VU17355

Vulnerability risk: Low

CVSSv3.1: 6.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C]

CVE-ID: CVE-2019-3810

CWE-ID: CWE-264

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
Moodle
Web applications / Other software

Vendor: moodle.org

Description

The vulnerability allows a remote attacker to bypass security restrictions.

The vulnerability exists due to the /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. A remote attacker can bypass security restrictions to conduct further attacks.

Mitigation
The vulnerability has been addressed in the versions 3.1.16, 3.4.7, 3.5.4, 3.6.2.

Vulnerable software versions

Moodle: 3.4.0 - 3.4.6, 3.6.0 - 3.6.1, 3.3.5, 3.5.0 - 3.5.2, 3.1.0 - 3.1.15


External links
http://moodle.org/mod/forum/discuss.php?d=381230


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability