CVE-2019-14879: Moodle

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).

Affected products

  • Moodle Moodle: from 3.5.0, up to and including 3.5.8; from 3.6.0, up to and including 3.6.6; from 3.7.0, up to and including 3.7.2

Published 2020-01-07. Last modified 2026-06-17.