CVE-2018-1042

MEDIUM

Moodle < 3.1.9 and 3.4-3.4.1 - Server-Side Request Forgery via Filepicker

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-1042. PoCs published by Fabian Mosch_ Nick Theisinger, UDPsycho.

AI-analyzed exploit summary This exploit demonstrates a Server Side Request Forgery (SSRF) vulnerability in Moodle's filepicker functionality. It allows an authenticated attacker to perform internal port scans and interact with internal web services via HTTP GET requests.

Description

Moodle 3.x has Server Side Request Forgery in the filepicker.

Exploits (2)

exploitdb WORKING POC
by Fabian Mosch_ Nick Theisinger · textwebappsphp
https://www.exploit-db.com/exploits/47177

This exploit demonstrates a Server Side Request Forgery (SSRF) vulnerability in Moodle's filepicker functionality. It allows an authenticated attacker to perform internal port scans and interact with internal web services via HTTP GET requests.

Classification
Working Poc 90%
Attack Type
Ssrf
Complexity
Moderate
Reliability
Reliable
Target: Moodle versions 3.4, 3.3, 3.3.3, 3.2 to 3.2.6, 3.1 to 3.1.9, and 3.5.2
Auth required
Prerequisites: Authenticated access to a vulnerable Moodle instance
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 2 stars
by UDPsycho · poc
https://github.com/UDPsycho/Moodle-CVE-2018-1042

This is a Python script that exploits CVE-2018-1042, an SSRF vulnerability in Moodle, to perform internal port scans. It sends crafted requests to a Moodle server to probe internal ports on a specified target IP.

Classification
Working Poc 95%
Attack Type
Ssrf
Complexity
Moderate
Reliability
Reliable
Target: Moodle (versions affected by CVE-2018-1042)
Auth required
Prerequisites: Valid Moodle session cookie · Access to the Moodle repository_ajax.php endpoint · Target IP address to scan
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=364381
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/102752

Scores

CVSS v3 6.5
EPSS 0.1287
EPSS Percentile 94.2%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-918
Status published
Products (14)
moodle/moodle 3.2.0
moodle/moodle 3.2.1
moodle/moodle 3.2.2
moodle/moodle 3.2.3
moodle/moodle 3.2.4
moodle/moodle 3.2.5
moodle/moodle 3.2.6
moodle/moodle 3.3.0
moodle/moodle 3.3.1
moodle/moodle 3.3.2
... and 4 more
Published Jan 22, 2018
Tracked Since Feb 18, 2026