Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qv78-6gpp-hm68

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 3.5

Описание

Moodle Open Redirect vulnerability

A flaw was found in Moodle. An Open Redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.1.22

4.1.22

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.4.0-beta, < 4.4.12

4.4.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.8

4.5.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.4

5.0.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.1.0-beta, < 5.1.1

5.1.1

EPSS

Процентиль: 1%
0.00011
Низкий

3.5 Low

CVSS3

Дефекты

CWE-601

Связанные уязвимости

CVSS3: 3.5
ubuntu
4 дня назад

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

CVSS3: 3.5
nvd
4 дня назад

A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.

CVSS3: 3.5
debian
4 дня назад

A flaw was found in Moodle. An open redirect vulnerability in the OAut ...

EPSS

Процентиль: 1%
0.00011
Низкий

3.5 Low

CVSS3

Дефекты

CWE-601