CVE-2019-10188: Moodle

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A flaw was found in moodle before versions 3.7.1, 3.6.5, 3.5.7. Teachers in a quiz group could modify group overrides for other groups in the same quiz.

Affected products

  • Moodle Moodle: before 3.5.7 (fixed in 3.5.7); from 3.6.0, before 3.6.5 (fixed in 3.6.5); from 3.7.0, before 3.7.1 (fixed in 3.7.1)

Published 2019-07-31. Last modified 2026-06-17.