Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2010-0892 Vulnerability (CVE-2010-0892)
WordPress Plugin Accept Donations with PayPal Cross-Site Request Forgery (1.3)
MediaWiki Improper Input Validation Vulnerability (CVE-2021-31555)
WordPress Plugin Premmerce Wholesale Pricing for WooCommerce Security Bypass (1.1.3)
MediaWiki Improper Input Validation Vulnerability (CVE-2011-1580)