Description
course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.
Remediation
References
Related Vulnerabilities
Joomla! Core 3.x.x Cross-Site Scripting (3.1.2 - 3.2.2)
MODX Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2017-7321)
Oracle Database Server CVE-2015-2585 Vulnerability (CVE-2015-2585)
WordPress Plugin SocialGrid 'default_services' Parameter Cross-Site Scripting (2.3)
Jenkins Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2017-2603)