CVE-2019-3809
Moodle Blind SSRF Risk in /badges/mybackpack.php
10.0
CRITICAL
CVSS 3.1
EPSS 0.26%
Description
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
How to fix CVE-2019-3809
To remediate CVE-2019-3809, upgrade the affected package to a fixed version below.
- —upgrade to 3.1.16 or later
Is CVE-2019-3809 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.1, < 3.1.16
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | CRITICAL10.0 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |