Логотип exploitDog
bind: "CVE-2022-45149"
Консоль
Логотип exploitDog

exploitDog

bind: "CVE-2022-45149"

Количество 6

Количество 6

ubuntu логотип

CVE-2022-45149

больше 2 лет назад

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2022-45149

больше 2 лет назад

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2022-45149

больше 2 лет назад

A vulnerability was found in Moodle which exists due to insufficient v ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-8v23-w4w5-w83c

больше 2 лет назад

Cross-Site Request Forgery in Moodle

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2022-07405

больше 2 лет назад

Уязвимость системы управления курсами Moodle, связанная с недостаточной проверкой источника HTTP-запроса в URL-адресе перенаправления курса, позволяющая нарушителю выполнять атаки с подделкой межсайтовых запросов

CVSS3: 5.4
EPSS: Низкий
redos логотип

ROS-20221222-03

больше 2 лет назад

Множественные уязвимости moodle

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2022-45149

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
nvd логотип
CVE-2022-45149

A vulnerability was found in Moodle which exists due to insufficient validation of the HTTP request origin in course redirect URL. A user's CSRF token was unnecessarily included in the URL when being redirected to a course they have just restored. A remote attacker can trick the victim to visit a specially crafted web page and perform arbitrary actions on behalf of the victim on the vulnerable website. This flaw allows an attacker to perform cross-site request forgery attacks.

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
debian логотип
CVE-2022-45149

A vulnerability was found in Moodle which exists due to insufficient v ...

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
github логотип
GHSA-8v23-w4w5-w83c

Cross-Site Request Forgery in Moodle

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2022-07405

Уязвимость системы управления курсами Moodle, связанная с недостаточной проверкой источника HTTP-запроса в URL-адресе перенаправления курса, позволяющая нарушителю выполнять атаки с подделкой межсайтовых запросов

CVSS3: 5.4
0%
Низкий
больше 2 лет назад
redos логотип
ROS-20221222-03

Множественные уязвимости moodle

CVSS3: 9.1
больше 2 лет назад

Уязвимостей на страницу