A vulnerability was found in moodle before versions 3.6.3 and 3.5.5. There was a link to site home within the the Boost theme's secure layout, meaning students could navigate out of the page.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-3851.json"