CVE-2019-3849
26.03.2019, 18:29
A vulnerability was found in moodle before versions 3.6.3, 3.5.5 and 3.4.8. Users could assign themselves an escalated role within courses or content accessed via LTI, by modifying the request to the LTI publisher site.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 3.4.8 |
moodle | moodle | 3.5.0 ≤ 𝑥 < 3.5.5 |
moodle | moodle | 3.6.0 ≤ 𝑥 < 3.6.3 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-285 - Improper AuthorizationThe software does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
- CWE-269 - Improper Privilege ManagementThe software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.