6.1
CVSSv3

CVE-2019-3810

Published: 25/03/2019 Updated: 07/11/2022
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and previous versions unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle

Exploits

Moodle version 361 suffers from a persistent cross site scripting vulnerability ...

Github Repositories

Moodle (< 3.6.2, < 3.5.4, < 3.4.7, < 3.1.16) XSS PoC for Privilege Escalation (Student to Admin)

Moodle CVE-2019-3810 Moodle (&lt; 362, &lt; 354, &lt; 347, &lt; 3116) XSS PoC for Privilege Escalation (Student to Admin) This is one of the past bugs that I discovered during past pentest in an academic institution It was successful enough at the time to practically steal admin access and gain complete control over Moodle using just one simple bug We