Multiple open redirect vulnerabilities in Moodle 2.2.x prior to 2.2.7, 2.3.x prior to 2.3.4, and 2.4.x prior to 2.4.1 allow remote malicious users to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
moodle moodle 2.2.4 |
||
moodle moodle 2.2.5 |
||
moodle moodle 2.2.0 |
||
moodle moodle 2.2.3 |
||
moodle moodle 2.2.2 |
||
moodle moodle 2.2.1 |
||
moodle moodle 2.2.6 |
||
moodle moodle 2.3.0 |
||
moodle moodle 2.3.2 |
||
moodle moodle 2.3.3 |
||
moodle moodle 2.3.1 |
||
moodle moodle 2.4.0 |