Blind SSRF Risk Due to Insufficient Redirect Handling in Moodle
CVE-2021-36396

7.5HIGH

Key Information:

Vendor

Moodle

Status
Vendor
CVE Published:
6 March 2023

What is CVE-2021-36396?

In Moodle, an oversight in the handling of redirects allows for exploitation through Server-Side Request Forgery (SSRF) attacks. This vulnerability enables attackers to bypass cURL's blocked hosts and allowed ports, facilitating unauthorized requests from the server to internal services or other external systems. The improper validation of redirects can result in severe security implications, necessitating immediate attention and remediation by system administrators.

Affected Version(s)

Moodle 3.11, 3.10 to 3.10.4, 3.9 to 3.9.7 and earlier unsupported versions

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.