Vulnerability Bulletins |
MSA-18-0001: Server Side Request Forgery in the filepicker |
|
| Affected software | PHP |
|
by Marina Glancy. By substituting the source URL in the filepicker AJAX request authenticated users are able to retrieve and view any URL. We classify this issue as serious because some cloud hosting providers contain internal resources that can expose data and compromise a serverSeverity/Risk:SeriousVersions affected:3.4, 3.3 to 3.3.3, 3.2 to 3.2.6, 3.1 to 3.1.9 and earlier unsupported versionsVersions fixed:3.4.1, 3.3.4, 3.2.7 and 3.1.10Reported by:Thomas DeVossCVE More info: https://moodle.org/mod/forum/discuss.php?d=364381&parent=1469490 |
|






