Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5xp2-rv4h-mm2q

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Moodle Open Redirect Vulnerability

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6.0, <= 3.6.3

3.6.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5.0, <= 3.5.5

3.5.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.4.0, <= 3.4.8

3.4.9

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

<= 3.1.17

3.1.18

EPSS

Процентиль: 37%
0.00153
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 3.1
ubuntu
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
nvd
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.

CVSS3: 3.1
debian
почти 6 лет назад

A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. ...

EPSS

Процентиль: 37%
0.00153
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-601