Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jp4g-r8c9-3534

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 10

Описание

Moodle Blind SSRF Risk in /badges/mybackpack.php

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.1, < 3.1.16

3.1.16

EPSS

Процентиль: 51%
0.00279
Низкий

10 Critical

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 6 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
nvd
около 6 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

CVSS3: 6.5
debian
около 6 лет назад

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsuppor ...

EPSS

Процентиль: 51%
0.00279
Низкий

10 Critical

CVSS3

Дефекты

CWE-918