PT-2012-1842 · Moodle · Moodle
Kurt Seifried
·
Published
2012-07-16
·
Updated
2022-05-13
·
CVE-2011-4294
CVSS v2.0
5.8
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Moodle versions 1.9.x through 1.9.12
Moodle versions 2.0.x through 2.0.3
Moodle versions 2.1.x through 2.1.0
Description
The error-message functionality does not ensure that a continuation link refers to an http or https URL for the local Moodle instance. This might allow attackers to trick users into visiting arbitrary web sites via error message links that lead offsite.
Recommendations
For Moodle versions 1.9.x through 1.9.12, update to version 1.9.13 or later.
For Moodle versions 2.0.x through 2.0.3, update to version 2.0.4 or later.
For Moodle versions 2.1.x through 2.1.0, update to version 2.1.1 or later.
Fix
Open Redirect
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moodle