CVE Database
/

CVE-2022-35652

Back to search

CVE-2022-35652

Published: Jul 25, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

An open redirect issue was found in Moodle due to improper sanitization of user-supplied data in mobile auto-login feature. A remote attacker can create a link that leads to a trusted website, however, when clicked, it redirects the victims to arbitrary URL/domain. Successful exploitation of this vulnerability may allow a remote attacker to perform a phishing attack and steal potentially sensitive information.

VendorProductVersions

n/a

Moodle

affected
Fixed in moodle 4.0.2, moodle 3.11.8, moodle 3.9.15

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now