PT-2022-5980 · Moodle+2 · Moodle+2

Holmec

+1

·

Published

2020-11-08

·

Updated

2024-03-06

·

CVE-2022-45152

CVSS v2.0

9.4

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A blind Server-Side Request Forgery (SSRF) vulnerability was found due to insufficient validation of user-supplied input in the LTI provider library. The library does not utilize Moodle's inbuilt cURL helper, resulting in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This allows a remote attacker to perform SSRF attacks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SSRF

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3235
ALT-PU-2020-3289
ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
BDU:2022-07408
BIT-MOODLE-2022-45152
CVE-2022-45152
GHSA-XQCF-VGQC-PCMG

Affected Products

Alt Linux
Moodle
Red Os