#VU17355 Security restrictions bypass in Moodle - CVE-2019-3810
Published: February 1, 2019 / Updated: June 17, 2021
Moodle
moodle.org
Description
The vulnerability allows a remote attacker to bypass security restrictions.
The vulnerability exists due to the /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. A remote attacker can bypass security restrictions to conduct further attacks.