USN-8805-1: Moodle vulnerability
AI summary · grok-4.7
Ubuntu warned that an authenticated Moodle user could attempt SSRF and expose sensitive information.
Ubuntu Security Notice USN-8805-1 says Moodle did not properly restrict URLs. An authenticated user could potentially use the flaw for server-side request forgery and expose sensitive information. The notice does not cite a CVE and does not report exploitation.
- Authenticated Moodle users could abuse unrestricted URLs for server-side request forgery.
- A successful request could expose sensitive information held by the server.
- Ubuntu issued USN-8805-1; the notice reports no active exploitation.
Full article
It was discovered that Moodle did not properly restrict URLs. An authenticated user could possibly use this issue to perform a server-side request forgery attack and expose sensitive information.
This source does not provide full text. Read it at ubuntu.com.