PT-2024-9765 · Moodle+2 · Moodle+2
Marina Glancy
·
Published
2024-08-07
·
Updated
2025-05-02
·
CVE-2024-43432
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Moodle (affected versions not specified)
Description:
A flaw was found in the cURL wrapper in Moodle, which strips HTTPAUTH and USERPWD headers during emulated redirects but retains other original request headers. This could lead to HTTP authorization header information being unintentionally sent in requests to redirect URLs, potentially allowing a remote attacker to gain unauthorized access to protected information.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Cleartext Transmission of Sensitive Information
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Moodle
Red Os