PT-2012-1842 · Moodle · Moodle
Kurt Seifried
·
Publicado
2012-07-16
·
Atualizado
2022-05-13
·
CVE-2011-4294
CVSS v2.0
5.8
Média
| Vetor | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moodle versions 1.9.x through 1.9.12
Moodle versions 2.0.x through 2.0.3
Moodle versions 2.1.x through 2.1.0
Description
The error-message functionality does not ensure that a continuation link refers to an http or https URL for the local Moodle instance. This might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.
Recommendations
For Moodle versions 1.9.x through 1.9.12, update to version 1.9.13 or later.
For Moodle versions 2.0.x through 2.0.3, update to version 2.0.4 or later.
For Moodle versions 2.1.x through 2.1.0, update to version 2.1.1 or later.
Correção
Open Redirect
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Moodle