CVE Vulnerabilities

CVE-2019-14829

Improper Following of Specification by Caller

Published: Mar 19, 2021 | Modified: Feb 12, 2023
CVSS 3.x
4.3
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM

A vulnerability was found in Moodle affection 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions where activity creation capabilities were not correctly respected when selecting the activity to use for a course in single activity mode.

Weakness

The product does not follow or incorrectly follows the specifications as required by the implementation language, environment, framework, protocol, or platform.

Affected Software

Name Vendor Start Version End Version
Moodle Moodle 3.5.0 (including) 3.5.7 (including)
Moodle Moodle 3.6.0 (including) 3.6.5 (including)
Moodle Moodle 3.7.0 (including) 3.7.1 (including)
Moodle Ubuntu bionic *
Moodle Ubuntu trusty *
Moodle Ubuntu xenial *

References