CVE-2019-10154: Moodle

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

A flaw was found in Moodle before versions 3.7, 3.6.4. A web service fetching messages was not restricted to the current user's conversations.

Affected products

  • Moodle Moodle: before 3.6.4 (fixed in 3.6.4)

Published 2019-06-26. Last modified 2026-06-17.