Description
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
Remediation
References
Related Vulnerabilities
Moodle Permissions, Privileges, and Access Controls Vulnerability (CVE-2014-0122)
Magento CVE-2020-9585 Vulnerability (CVE-2020-9585)
Chamilo Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2023-4224)
SharePoint CVE-2022-38009 Vulnerability (CVE-2022-38009)
WordPress Plugin Video Embed & Thumbnail Generator Cross-Site Scripting (4.0.3)