ZeroHour

CVE-2024-38275

CVSS 3.1
7.5 high
EPSS
<1%p38
Published
()
Modified
Description

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

Vendors
moodle
Products
moodle
Weakness
CWE-226, CWE-459
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.