Headline
GHSA-4rmj-w58m-fvch: Moodle vulnerable to Server-Side Request Forgery
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
Moodle vulnerable to Server-Side Request Forgery
Moderate severity GitHub Reviewed Published Mar 6, 2023 to the GitHub Advisory Database • Updated Mar 7, 2023
Related news
CVE-2021-36396
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.