CVE-2019-3851: Fedoraproject Fedora
Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.
A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
Affected products
- Fedoraproject Fedora: affected versions not specified
- Moodle Moodle: from 3.5.0, before 3.5.5 (fixed in 3.5.5); from 3.6.0, before 3.6.3 (fixed in 3.6.3)
Published 2019-03-26. Last modified 2026-06-17.