An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/104307 | Third Party Advisory VDB Entry |
https://moodle.org/mod/forum/discuss.php?d=371204 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2018-05-25 12:29
Updated : 2024-02-04 19:46
NVD link : CVE-2018-1137
Mitre link : CVE-2018-1137
CVE.ORG link : CVE-2018-1137
JSON object : View
Products Affected
moodle
- moodle
CWE
CWE-20
Improper Input Validation