Description
Moodle through 2.6.11, 2.7.x before 2.7.13, 2.8.x before 2.8.11, 2.9.x before 2.9.5, and 3.0.x before 3.0.3 does not properly restrict links, which allows remote attackers to obtain sensitive URL information by reading a Referer log.
Remediation
References
Related Vulnerabilities
WebLogic CVE-2018-3201 Vulnerability (CVE-2018-3201)
WordPress Plugin UserPro-Community and User Profile Cross-Site Scripting (4.9.33)
Python Integer Overflow or Wraparound Vulnerability (CVE-2022-37454)
MySQL CVE-2021-35647 Vulnerability (CVE-2021-35647)
IBM WebSEAL Incorrect Default Permissions Vulnerability (CVE-2023-38370)