PT-2012-1842 · Moodle · Moodle

Kurt Seifried

·

Published

2012-07-16

·

Updated

2022-05-13

·

CVE-2011-4294

CVSS v2.0

5.8

Medium

VectorAV:N/AC:M/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions 1.9.x through 1.9.12 Moodle versions 2.0.x through 2.0.3 Moodle versions 2.1.x through 2.1.0
Description The error-message functionality does not ensure that a continuation link refers to an http or https URL for the local Moodle instance. This might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.
Recommendations For Moodle versions 1.9.x through 1.9.12, update to version 1.9.13 or later. For Moodle versions 2.0.x through 2.0.3, update to version 2.0.4 or later. For Moodle versions 2.1.x through 2.1.0, update to version 2.1.1 or later.

Fix

Open Redirect

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-4294
DSA-2338-1
GHSA-HXMP-8F47-X9FC

Affected Products

Moodle