CVE-2019-3851: Fedoraproject Fedora

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.

Affected products

  • Fedoraproject Fedora: affected versions not specified
  • Moodle Moodle: from 3.5.0, before 3.5.5 (fixed in 3.5.5); from 3.6.0, before 3.6.3 (fixed in 3.6.3)

Published 2019-03-26. Last modified 2026-06-17.