← back
CVE-2023-35133

Moodle: ssrf risk due to insufficient check on the curl blocked hosts

CVSS 7.5 HIGHEPSS 0.8%CWE-918
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.5EPSS 0.8%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
22 Jun 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
moodle

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →