CVE-2024-38275
7.5HIGHThe cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Publicado: 6/18/2024Actualizado: 4/30/2025
Descripción
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Análisis IAImpulsado por IA
Productos Afectados
moodlemoodle
moodlemoodle
moodlemoodle
moodlemoodle
4.4.0
Referencias
- https://moodle.org/mod/forum/discuss.php?d=459500Vendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=459500Vendor Advisory