Description Moodle 3.x has Server Side Request Forgery in the filepicker. Remediation References CVE-2018-1042 Related Vulnerabilities WordPress Plugin Simple PDF Viewer Cross-Site Scripting (1.9) WordPress Plugin Caret Country Access Limit Cross-Site Scripting (1.0.1) WordPress Plugin VikBooking Hotel Booking Engine & PMS Multiple Cross-Site Request Forgery Vulnerabilities (1.5.12) jQuery Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2012-6708) Plone CMS Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') Vulnerability (CVE-2012-5507) Severity Medium Classification CVE-2018-1042 CWE-918 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities