First published: Wed Jul 31 2019(Updated: )
A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.7.0<3.7.1 | 3.7.1 |
composer/moodle/moodle | >=3.6.0<3.6.5 | 3.6.5 |
composer/moodle/moodle | <3.5.7 | 3.5.7 |
Moodle | <3.5.7 | |
Moodle | >=3.6.0<3.6.5 | |
Moodle | >=3.7.0<3.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10188 is classified as a medium severity vulnerability.
To address CVE-2019-10188, upgrade your Moodle installation to version 3.7.1 or later, 3.6.5 or later, or 3.5.7.
CVE-2019-10188 affects teacher accounts in a quiz group, allowing them to modify group overrides for other groups.
Moodle versions prior to 3.7.1, 3.6.5, and 3.5.7 are vulnerable to CVE-2019-10188.
CVE-2019-10188 can result in unauthorized modifications to group overrides in quizzes, potentially affecting test integrity.