PT-2022-8588 · Moodle+1 · Moodle+1

Brendan Heywood

·

Published

2020-03-10

·

Updated

2024-03-06

·

CVE-2020-1755

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.8.2 Moodle versions prior to 3.7.5 Moodle versions prior to 3.6.9 Moodle versions prior to 3.5.11
Description The issue allows X-Forwarded-For headers to be used to spoof a user's IP, bypassing remote address checks.
Recommendations For versions prior to 3.8.2, update to version 3.8.2 or later. For versions prior to 3.7.5, update to version 3.7.5 or later. For versions prior to 3.6.9, update to version 3.6.9 or later. For versions prior to 3.5.11, update to version 3.5.11 or later.

Fix

Insufficient Verification of Data Authenticity

Weakness Enumeration

Related Identifiers

ALT-PU-2020-1443
ALT-PU-2020-1977
BIT-MOODLE-2020-1755
CVE-2020-1755

Affected Products

Alt Linux
Moodle