Description
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Embed PDF Cross-Site Scripting (1.0.6)
WordPress Plugin Multi Step Form Multiple Cross-Site Scripting Vulnerabilities (1.2.5)
WordPress Plugin WP-UserOnline URL HTML Injection (2.62)
e107 Other Vulnerability (CVE-2005-1949)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2021-3629)