A flaw was found in moodle versions 3.6 to 3.6.1, 3.5 to 3.5.3, 3.4 to 3.4.6, 3.1 to 3.1.15 and earlier unsupported versions. The /userpix/ page did not escape users' full names, which are included as text when hovering over profile images. Note this page is not linked to by default and its access is restricted.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-wm4w-8vc6-2j4h Moodle XSS Vulnerability
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.04584}

epss

{'score': 0.08846}


cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-04T19:19:18.619Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3810

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-25T18:29:00.807

Modified: 2024-11-21T04:42:35.250

Link: CVE-2019-3810

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.