Description
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin Another WordPress Classifieds Arbitrary File Upload (3.3.2)
WebLogic Improper Input Validation Vulnerability (CVE-2019-12400)
WordPress Plugin Gallery Objects SQL Injection (0.4)
Python Untrusted Search Path Vulnerability (CVE-2023-41105)
WordPress Plugin WordPress Backup to Dropbox Cross-Site Scripting (4.0)