Description
An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.
Remediation
References
Related Vulnerabilities
WordPress Plugin Count per Day Multiple Cross-Site Scripting Vulnerabilities (3.5.4)
Oracle JRE CVE-2013-2470 Vulnerability (CVE-2013-2470)
PostgreSQL Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-3488)
WordPress Plugin WP Database Backup Cross-Site Request Forgery (4.3.5)
Dolibarr Improper Privilege Management Vulnerability (CVE-2022-43138)