Record summary

CVE-2018-1042 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

Moodle 3.x has Server Side Request Forgery in the filepicker.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus

Moodle 3.x

CVE ListMoodle 3.xaffected
GitHub Advisory3.4 to < 3.4.1 · Fixed in 3.4.1affected
3.3 to < 3.3.4 · Fixed in 3.3.4affected
3.2 to < 3.2.7 · Fixed in 3.2.7affected
3.1 to < 3.1.10 · Fixed in 3.1.10affected

Proofs of concept

2

Catalogued exploits

ExploitDBMoodle Filepicker 3.5.2 - Server Side Request ForgeryExploitDB exploitby Fabian Mosch_ Nick TheisingerNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubUDPsycho/Moodle-CVE-2018-1042Repository PoCby UDPsychoStars: 2Not analyzed3 files

3.5 KiB

GitHub

PoC details

References

6