Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Remediation
References
Related Vulnerabilities
GibbonEdu CVE-2023-45878 Vulnerability (CVE-2023-45878)
WordPress Plugin Category Grid View Gallery TimThumb Arbitrary File Upload (0.1.1)
Jboss EAP Permissions, Privileges, and Access Controls Vulnerability (CVE-2015-5304)
Nginx Integer Overflow or Wraparound Vulnerability (CVE-2017-20005)
Oracle Database Server CVE-2016-0499 Vulnerability (CVE-2016-0499)