PT-2012-1842 · Moodle · Moodle
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moodle versions 1.9.x through 1.9.12
Moodle versions 2.0.x through 2.0.3
Moodle versions 2.1.x through 2.1.0
Description
The error-message functionality does not ensure that a continuation link refers to an http or https URL for the local Moodle instance. This might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.
Recommendations
For Moodle versions 1.9.x through 1.9.12, update to version 1.9.13 or later.
For Moodle versions 2.0.x through 2.0.3, update to version 2.0.4 or later.
For Moodle versions 2.1.x through 2.1.0, update to version 2.1.1 or later.
Correção
RCE
Open Redirect
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Moodle