CVE-2019-10154: Moodle
High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.
A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.
Affected products
- Moodle Moodle: before 3.6.4 (fixed in 3.6.4)
Published 2019-06-26. Last modified 2026-06-17.