Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-73q4-xm6m-m55x

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

EPSS

Процентиль: 56%
0.00333
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

nvd
больше 18 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

debian
больше 18 лет назад

course/jumpto.php in Moodle before 1.6.2 does not validate the session ...

EPSS

Процентиль: 56%
0.00333
Низкий