Open Redirect Vulnerabilities in Moodle 2.2.x, 2.3.x, and 2.4.x

Open Redirect Vulnerabilities in Moodle 2.2.x, 2.3.x, and 2.4.x

CVE-2012-6101 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:P/A:N

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php, (2) comment/comment_post.php, (3) course/switchrole.php, (4) mod/wiki/filesedit.php, (5) tag/coursetags_add.php, or (6) user/files.php.

Learn more about our Web App Pen Testing.