Описание
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
Ссылки
- Third Party Advisory
- Third Party AdvisoryIssue Tracking
Уязвимые конфигурации
Одно из
EPSS
3.5 Low
CVSS3
6.1 Medium
CVSS3
Дефекты
Связанные уязвимости
A flaw was found in Moodle. An open redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
A flaw was found in Moodle. An open redirect vulnerability in the OAut ...
EPSS
3.5 Low
CVSS3
6.1 Medium
CVSS3