CVE-2018-1081

A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

History

21 Nov 2024, 03:59

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/103728 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/103728 - Third Party Advisory, VDB Entry
References () https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-61392 - Patch, Vendor Advisory () https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-61392 - Patch, Vendor Advisory
References () https://moodle.org/mod/forum/discuss.php?d=367938 - Vendor Advisory () https://moodle.org/mod/forum/discuss.php?d=367938 - Vendor Advisory

Information

Published : 2018-04-04 21:29

Updated : 2024-11-21 03:59


NVD link : CVE-2018-1081

Mitre link : CVE-2018-1081

CVE.ORG link : CVE-2018-1081


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

NVD-CWE-noinfo