Description Moodle 3.x has Server Side Request Forgery in the filepicker. Remediation References CVE-2018-1042 Related Vulnerabilities Jenkins Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Vulnerability (CVE-2021-21683) Artifactory Weak Password Requirements Vulnerability (CVE-2019-17444) Piwigo Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2015-1517) Drupal Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2020-11023) Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0018) Severity Medium Classification CVE-2018-1042 CWE-918 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities