Security Advisory
CVE-2019-14831
CVE vulnerability detail — eXtreme Datacenter Security Operations
Description
A vulnerability was found in Moodle 3.7 to 3.7.1, 3.6 to 3.6.5, 3.5 to 3.5.7 and earlier unsupported versions, where forum subscribe link contained an open redirect if forced subscription mode was enabled. If a forums subscription mode was set to "forced subscription", the forums subscribe link contained an open redirect.