← back
CVE-2019-3849mediumCWE-285

CVE-2019-3849

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.3epss 1.0%
exploitation probability
1.0%top 38% of all CVEs
observed exploitation
nono source reports it
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Affected products
[UNKNOWN] · moodle