Description
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.
Remediation
References
Related Vulnerabilities
Envoy Proxy Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2023-27492)
WordPress Plugin Nifty Newsletters (Formerly Sola Newsletters) Cross-Site Request Forgery (4.0.23)
ownCloud Other Vulnerability (CVE-2012-5609)
WordPress Plugin WordPress Download Manager Cross-Site Scripting (2.9.86)