Description
A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2935 | A vulnerability was found in Moodle 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens used to fetch inline atachments in email notifications were not disabled when a user's account was no longer active. Note: to access files, a user would need to know the file path, and their token. |
Github GHSA |
GHSA-774q-wfcp-vc2q | Moodle Email media URL tokens were not checking for user status |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T00:26:39.123Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14883
No data.
Status : Modified
Published: 2020-03-18T13:15:12.027
Modified: 2024-11-21T04:27:36.270
Link: CVE-2019-14883
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA