GHSA-jp4g-r8c9-3534
Dashboard / Vulnerabilities / GHSA-jp4g-r8c9-3534
Summary: Moodle Blind SSRF Risk in /badges/mybackpack.php
Details: A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.
References: https://nvd.nist.gov/vuln/detail/CVE-2019-3809, https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-3809, https://github.com/moodle/moodle, https://moodle.org/mod/forum/discuss.php?d=381229#p1536766, http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-64222
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
