An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104307 | Third Party Advisory VDB Entry |
https://moodle.org/mod/forum/discuss.php?d=371204 | Vendor Advisory |
http://www.securityfocus.com/bid/104307 | Third Party Advisory VDB Entry |
https://moodle.org/mod/forum/discuss.php?d=371204 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:59
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/104307 - Third Party Advisory, VDB Entry | |
References | () https://moodle.org/mod/forum/discuss.php?d=371204 - Vendor Advisory |
Information
Published : 2018-05-25 12:29
Updated : 2024-11-21 03:59
NVD link : CVE-2018-1137
Mitre link : CVE-2018-1137
CVE.ORG link : CVE-2018-1137
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-20
Improper Input Validation