Vulnerability CVE-2019-14830


Published: 2021-03-19

Description:
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where the mobile launch endpoint contained an open redirect in some circumstances, which could result in a user's mobile access token being exposed. (Note: This does not affect sites with a forced URL scheme configured, mobile service disabled, or where the mobile app login method is "via the app").

Type:

CWE-601

(URL Redirection to Untrusted Site ('Open Redirect'))

CVSS2 => (AV:N/AC:M/Au:N/C:P/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.8/10
4.9/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
None
Affected software
Moodle -> Moodle 

 References:
https://git.moodle.org/gw?p=moodle.git;a=commit;h=d4985a77391123c5959db432c076328f8d5e3624
https://moodle.org/mod/forum/discuss.php?d=391036

Copyright 2024, cxsecurity.com

 

Back to Top