Multiple vulnerabilities in Moodle



Published: 2018-01-22 | Updated: 2022-07-30
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE-ID CVE-2018-1042
CVE-2018-1043
CVE-2018-1044
CWE-ID CWE-918
CWE-20
CWE-200
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
Moodle
Web applications / Other software

Vendor moodle.org

Security Bulletin

This security bulletin contains information about 3 vulnerabilities.

1) Server-Side Request Forgery (SSRF)

EUVDB-ID: #VU37616

Risk: Medium

CVSSv3.1: 5.9 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:P/RL:O/RC:C]

CVE-ID: CVE-2018-1042

CWE-ID: CWE-918 - Server-Side Request Forgery (SSRF)

Exploit availability: Yes

Description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

Moodle 3.x has Server Side Request Forgery in the filepicker.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Moodle: 3.2.0 - 3.4.0

External links

http://packetstormsecurity.com/files/153766/Moodle-Filepicker-3.5.2-Server-Side-Request-Forgery.html
http://www.securityfocus.com/bid/102752
http://moodle.org/mod/forum/discuss.php?d=364381


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

2) Input validation error

EUVDB-ID: #VU37617

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-1043

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to manipulate data.

In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Moodle: 3.2.0 - 3.4.0

External links

http://www.securityfocus.com/bid/102769
http://moodle.org/mod/forum/discuss.php?d=364382


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Information disclosure

EUVDB-ID: #VU37618

Risk: Low

CVSSv3.1: 3.8 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2018-1044

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote authenticated user to gain access to sensitive information.

In Moodle 3.x, quiz web services allow students to see quiz results when it is prohibited in the settings.

Mitigation

Install update from vendor's website.

Vulnerable software versions

Moodle: 3.2.0 - 3.4.0

External links

http://www.securityfocus.com/bid/102754
http://moodle.org/mod/forum/discuss.php?d=364383


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###