← Back

CVE-2019-14831

nvd nist
Published: Mar 19, 2021Modified: Jun 17, 2026

JSON object

Loading...
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD

Description

A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forum's subscription mode was set to "forced subscription", the forum's subscribe link contained an open redirect.

Affected (3)

Products: Moodle: Moodle
1 product
Moodle
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.5.0 to 3.5.7
From 3.6.0 to 3.6.5
From 3.7.0 to 3.7.1

References (4)

Source: secalert@redhat.com
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.