{"id":"CVE-2019-3851","details":"A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.","aliases":["GHSA-pj45-hp8h-289r"],"modified":"2026-05-18T14:17:16.570266Z","published":"2019-03-26T18:29:00.887Z","references":[{"type":"FIX","url":"https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3851"},{"type":"FIX","url":"https://moodle.org/mod/forum/discuss.php?d=384014#p1547746"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moodle/moodle","events":[{"introduced":"46574904afd39578fa4146bf1fc5c401ac680aa6"},{"fixed":"5e878219fbe7ab63d2a54ed02aff63443fb83192"},{"introduced":"cb628a9a08933c2a9f1eae2f3be70ea5d343b419"},{"fixed":"4d3a32dde97e964ad4512c35d15a1784c69c247e"}],"database_specific":{"source":"CPE_FIELD","extracted_events":[{"introduced":"3.5.0"},{"fixed":"3.5.5"},{"introduced":"3.6.0"},{"fixed":"3.6.3"}],"cpe":"cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"}}],"versions":["v3.5.4","v3.6.2","v3.6.0","v3.6.1","v3.5.3","v3.5.2","v3.5.1","v3.5.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-3851.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N"}]}