CVE Vulnerabilities

CVE-2019-14829

Improper Following of Specification by Caller

Published: Mar 19, 2021 | Modified: Nov 21, 2024
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

Weakness

The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.

Affected Software

NameVendorStart VersionEnd Version
MoodleMoodle3.5.0 (including)3.5.7 (including)
MoodleMoodle3.6.0 (including)3.6.5 (including)
MoodleMoodle3.7.0 (including)3.7.1 (including)
MoodleUbuntubionic*
MoodleUbuntutrusty*
MoodleUbuntuxenial*

References