CVE-2019-10134 describes a low-severity flaw in Moodle versions prior to 3.7, 3.6.4, 3.5.6, 3.4.9, and 3.1.18. The vulnerability allowed users to exceed their private file upload quota via email due to incorrect size checks. With a CVSS score of 3.7 (low), this issue has a network attack vector and low impact, primarily affecting data integrity (L) by allowing quota circumvention. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage, indicating a low likelihood of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1.0, <= 3.1.17CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.4.0, <= 3.4.8CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.5.0, <= 3.5.5CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.6.0, <= 3.6.3CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.