CVE-2019-3809

CVE-2019-3809

A flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, when it should be restricted to the Mozilla Open Badges backpack URL. This resulted in the possibility of blind SSRF via requests made by the page.

Source: CVE-2019-3809

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다