Описание
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
Ссылки
- PatchVendor Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
- PatchVendor Advisory
- Issue TrackingPatchThird Party Advisory
- PatchVendor Advisory
Уязвимые конфигурации
EPSS
6.5 Medium
CVSS3
10 Critical
CVSS3
7.5 High
CVSS2
Дефекты
Связанные уязвимости
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsuppor ...
EPSS
6.5 Medium
CVSS3
10 Critical
CVSS3
7.5 High
CVSS2