SSRF Vulnerability in Moodle by Moodle
CVE-2023-35133
7.5HIGH
What is CVE-2023-35133?
A flaw in the logic for validating the IP address 0.0.0.0 against the cURL blocked hosts lists presents an SSRF risk for various versions of Moodle. This issue may allow attackers to bypass security restrictions and make unauthorized requests to internal resources, potentially leading to information disclosure or further exploitation within the network. The impacted versions include Moodle 4.2, multiple 4.1 and 4.0 iterations, as well as 3.11 and 3.9 releases, along with earlier unsupported versions. Users are urged to apply necessary patches to mitigate the risk.
Affected Version(s)
moodle 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions