CVE-2024-38275
—CVSS 3.1
7.5 high
EPSS
<1%p38
Published
()
Modified
Description
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
- Vendors
- moodle
- Products
- moodle
- Weakness
- CWE-226, CWE-459
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.