CVE-2019-3810
Moodle XSS Vulnerability
5.3
MEDIUM
CVSS 3.1
EPSS 13.9%
Description
A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
How to fix CVE-2019-3810
To remediate CVE-2019-3810, upgrade the affected package to a fixed version below.
- —upgrade to 3.6.1 or later
Is CVE-2019-3810 being exploited?
Moderate — EPSS is 13.9%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- >= 3.6.0, < 3.6.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |