Moodle · Moodle · CVE-2022-35652
**Name of the Vulnerable Software and Affected Versions**
Moodle (affected versions not specified)
**Description**
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in the mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to an arbitrary URL/domain. Successful exploitation of this issue may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this issue.