CVE-2019-14879: Moodle
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
A vulnerability was found in Moodle versions 3.7.x before 3.7.3, 3.6.x before 3.6.7 and 3.5.x before 3.5.9. When a cohort role assignment was removed, the associated capabilities were not being revoked (where applicable).
Affected products
- Moodle Moodle: from 3.5.0, up to and including 3.5.8; from 3.6.0, up to and including 3.6.6; from 3.7.0, up to and including 3.7.2
Published 2020-01-07. Last modified 2026-06-17.