CVE-2019-3848
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Permissions were not correctly checked before loading event information into the calendar's edit event modal popup, so logged in non-guest users could view unauthorised calendar events. (Note: It was read-only access, users could not edit the events.)
Se ha detectado una vulnerabilidad en moodle, en versiones anteriores a la 3.6.3, 3.5.5 y 3.4.8. Los permisos no se comprobaban correctamente antes de cargar información de eventos en la ventana emergente modal de edición de eventos del calendario, por lo que los usuarios no invitados que hayan iniciado sesión podrían visualizar eventos de calendario no autorizados. (Nota: el acceso era de solo lectura, los usuarios no podían editar los eventos).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-01-03 CVE Reserved
- 2019-03-26 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-863: Incorrect Authorization
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3848 | 2022-11-07 | |
https://moodle.org/mod/forum/discuss.php?d=384011#p1547743 | 2022-11-07 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | < 3.4.8 Search vendor "Moodle" for product "Moodle" and version " < 3.4.8" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 3.5.0 < 3.5.5 Search vendor "Moodle" for product "Moodle" and version " >= 3.5.0 < 3.5.5" | - |
Affected
| ||||||
Moodle Search vendor "Moodle" | Moodle Search vendor "Moodle" for product "Moodle" | >= 3.6.0 < 3.6.3 Search vendor "Moodle" for product "Moodle" and version " >= 3.6.0 < 3.6.3" | - |
Affected
|