packetstormsecurity.com
http://packetstormsecurity.com/files/153766/Moodle-Filepicker-3.5.2-Server-Side-Request-Forgery.html CVE-2018-1042
MEDIUM
Moodle SSRF Vulnerability
Record summary
CVE-2018-1042 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Moodle 3.x | CVE List | Moodle 3.x | affected |
moodle/moodleBrowse Packagist / moodle/moodle | GitHub Advisory | 3.4 to < 3.4.1 · Fixed in 3.4.1 | affected |
| 3.3 to < 3.3.4 · Fixed in 3.3.4 | affected | ||
| 3.2 to < 3.2.7 · Fixed in 3.2.7 | affected | ||
| 3.1 to < 3.1.10 · Fixed in 3.1.10 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBMoodle Filepicker 3.5.2 - Server Side Request ForgeryExploitDB exploitby Fabian Mosch_ Nick TheisingerNot analyzed1 file
Repository PoCs
GitHubUDPsycho/Moodle-CVE-2018-1042Repository PoCby UDPsychoStars: 2Not analyzed3 files
References
6102752vdb entry
http://www.securityfocus.com/bid/102752 github.com
https://github.com/moodle/moodle/commit/f1d1a60e0ac8549c08e66062f3cd0110e4a92e24 moodle.orgConfirmation
https://moodle.org/mod/forum/discuss.php?d=364381 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-1042 web.archive.org
https://web.archive.org/web/20210124134113/http://www.securityfocus.com/bid/102752