VulnerabilityModified
CVE-2018-1081
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions.
MEDIUM 5.3EPSS 1.42%
Does this matter?
Lower severity and a low EPSS score (1.42%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.
- CVSS 3.1
- 5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/103728Third Party Advisory, VDB Entry
- https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-61392Patch, Vendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=367938Vendor Advisory
- http://www.securityfocus.com/bid/103728Third Party Advisory, VDB Entry
- https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-61392Patch, Vendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=367938Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.