PT-2024-27914 · Moodle+2 · Moodle+2

Cameron1729

·

Published

2024-06-18

·

Updated

2025-05-01

·

CVE-2024-38275

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The issue concerns the cURL wrapper in Moodle, which retains original request headers when following redirects. This could lead to HTTP authorization header information being unintentionally sent in requests to redirect URLs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16385
ALT-PU-2024-16417
BIT-MOODLE-2024-38275
CVE-2024-38275
GHSA-P2CJ-86V4-7782

Affected Products

Alt Linux
Moodle
Red Os