Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Remediation
References
Related Vulnerabilities
WordPress Plugin Survey Maker-Best WordPress Survey Cross-Site Scripting (2.0.6)
WordPress Plugin Chat-Support Board-WordPress Chat Privilege Escalation (3.3.8)
WordPress Plugin ReviewX-Multi-criteria Rating & Reviews for WooCommerce SQL Injection (1.6.8)
WordPress Plugin Backup and Staging by WP Time Capsule PHP Object Injection (1.21.9)