Server Side Request Forgery in Moodle Filepicker by Moodle
CVE-2018-1042
Key Information:
- Vendor
- Moodle
- Status
- Vendor
- CVE Published:
- 22 January 2018
Badges
Summary
Moodle versions 3.x are affected by a Server Side Request Forgery (SSRF) vulnerability in the filepicker component. This flaw allows attackers to craft requests that may relay sensitive information, potentially leading to unauthorized access to internal resources. The vulnerability occurs due to inadequate input validation, permitting maliciously crafted URLs. Organizations using affected Moodle versions should apply available patches immediately to protect their systems from potential exploits.
Affected Version(s)
Moodle 3.x Moodle 3.x
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
17% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved