CVE-2023-35133

An issue in the logic used to check 0.0.0.0 against the cURL blocked hosts lists resulted in an SSRF risk. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:4.2.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-06-22 21:15

Updated : 2024-04-19 14:15


NVD link : CVE-2023-35133

Mitre link : CVE-2023-35133

CVE.ORG link : CVE-2023-35133


JSON object : View

Products Affected

moodle

  • moodle
CWE
CWE-918

Server-Side Request Forgery (SSRF)