CVE-2018-1042
MEDIUMMoodle < 3.1.9 and 3.4-3.4.1 - Server-Side Request Forgery via Filepicker
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-1042. PoCs published by Fabian Mosch_ Nick Theisinger, UDPsycho.
AI-analyzed exploit summary This exploit demonstrates a Server Side Request Forgery (SSRF) vulnerability in Moodle's filepicker functionality. It allows an authenticated attacker to perform internal port scans and interact with internal web services via HTTP GET requests.
Description
Moodle 3.x has Server Side Request Forgery in the filepicker.
Exploits (2)
This exploit demonstrates a Server Side Request Forgery (SSRF) vulnerability in Moodle's filepicker functionality. It allows an authenticated attacker to perform internal port scans and interact with internal web services via HTTP GET requests.
This is a Python script that exploits CVE-2018-1042, an SSRF vulnerability in Moodle, to perform internal port scans. It sends crafted requests to a Moodle server to probe internal ports on a specified target IP.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N