First published: Wed Mar 18 2020(Updated: )
A vulnerability was found in Moodle 3.7 before 3.7.3, 3.6 before 3.6.7 and 3.5 before 3.5.9, where a reflected XSS possible from some fatal error messages.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.5.0<3.5.9 | 3.5.9 |
composer/moodle/moodle | >=3.6.0<3.6.7 | 3.6.7 |
composer/moodle/moodle | >=3.7.0<3.7.3 | 3.7.3 |
Moodle | >=3.5.0<3.5.9 | |
Moodle | >=3.6.0<3.6.7 | |
Moodle | >=3.7.0<=3.7.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-14884 is classified as a reflected cross-site scripting (XSS) vulnerability.
To remediate CVE-2019-14884, upgrade Moodle to versions 3.5.9, 3.6.7, or 3.7.3 or later.
CVE-2019-14884 affects Moodle versions 3.5.0 to 3.5.8, 3.6.0 to 3.6.6, and 3.7.0 to 3.7.2.
CVE-2019-14884 can enable attackers to execute arbitrary JavaScript in the context of the Moodle application.
Yes, CVE-2019-14884 can be exploited without authentication, making it critical for public-facing Moodle instances.