Unauthorized Message Triggering in Moodle by Users
CVE-2018-1081
What is CVE-2018-1081?
A vulnerability in Moodle allows unauthenticated users to exploit the PayPal enrolment script, leading to spam messages sent to administrators. The issue arises when the PayPal IPN callback script forwards error emails to admins without verifying the request's origin, potentially flooding their inboxes with unwanted messages. This flawed implementation in versions 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10, and earlier unsupported versions poses a significant risk to administrators, emphasizing the importance of validating requests before processing notifications.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved