9.1
CVSSv3

CVE-2022-45152

Published: 25/11/2022 Updated: 07/11/2023
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote malicious user to perform SSRF attacks.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle

fedoraproject fedora 35

fedoraproject fedora 36

fedoraproject extra packages for enterprise linux 7.0

fedoraproject fedora 37