Back to Database
Status published
Medium
CVE-2019-10134
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6,...
Vulnerability Description
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The size of users' private file uploads via email were not correctly checked, so their quota allowance could be exceeded.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10134
Credits & Attribution
No credits recorded in the NVD database.
References
More from Moodle
View All →CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows...
Medium
4.2
CVE-2025-34032
Moodle LMS Jmol Plugin Cross-site Scripting (XSS)
Medium
5.1
CVE-2025-34031
Moodle LMS Jmol Plugin Path Traversal
High
8.7
CVE-2024-38277
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Unknown
0
CVE-2024-38276
moodle: CSRF risks due to misuse of confirm_sesskey
Unknown
0
Affected Vendor
Moodle
View all reports →Affected Software
moodle
Vulnerable Versions:
3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18
Timeline
Official Publish:
June 26th, 2019
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L