Token Mismanagement Vulnerability in Moodle by Moodle HQ
CVE-2019-14883

3.7LOW

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
18 March 2020

What is CVE-2019-14883?

A security flaw was identified in Moodle versions 3.6 before 3.6.7 and 3.7 before 3.7.3, where tokens meant to fetch inline attachments in email notifications were improperly managed. These tokens remained active even after a user's account was deactivated, potentially allowing unauthorized access to sensitive files if the attacker knew the exact file path and possessed the token. This issue highlights the need for proper token management to safeguard user data and maintain system integrity.

Affected Version(s)

moodle 3.7.3

moodle 3.6.7

References

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.