Description
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Remediation
References
Related Vulnerabilities
MySQL CVE-2019-2791 Vulnerability (CVE-2019-2791)
WordPress Plugin Events Manager Cross-Site Scripting (5.9.5)
WordPress Plugin MM Forms Community 'doajaxfileupload.php' Arbitrary File Upload (2.2.6)
Artifactory Insufficient Verification of Data Authenticity Vulnerability (CVE-2018-19971)
WordPress Plugin 3xSocializer Cross-Site Scripting (0.98.22)