A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
{ "versions": [ { "introduced": "3.5.0" }, { "fixed": "3.5.5" }, { "introduced": "3.6.0" }, { "fixed": "3.6.3" } ] }
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-3851.json"