Lucene search

K
githubGitHub Advisory DatabaseGHSA-JCRJ-X36P-H9F6
HistoryMay 13, 2022 - 1:13 a.m.

Moodle Open Redirect in Calendar Set Page

2022-05-1301:13:15
CWE-601
GitHub Advisory Database
github.com
10
moodle
open redirect
calendar
vulnerability
remote authenticated users
phishing attacks
software

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

40.6%

Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.

Affected configurations

Vulners
Node
moodlemoodleRange<2.1.3

CVSS2

4.9

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:S/C:P/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.001

Percentile

40.6%