CVE-2022-35652

MEDIUM

Moodle 3.9.0-3.9.14 and 4.0-4.0.1 - Open Redirect via Mobile Auto-Login Feature

Title source: llm
STIX 2.1

Description

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

References (5)

Core 5

Scores

CVSS v3 6.1
EPSS 0.0038
EPSS Percentile 59.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-601
Status published
Products (4)
fedoraproject/fedora 35
fedoraproject/fedora 36
moodle/moodle 3.9.0 - 3.9.15
moodle/moodle 4.0 - 4.0.2Packagist
Published Jul 25, 2022
Tracked Since Feb 18, 2026