Description Moodle 3.x has Server Side Request Forgery in the filepicker. Remediation References CVE-2018-1042 Related Vulnerabilities Drupal Core 8.9.x Cross-Site Scripting (8.9.0 - 8.9.19) Joomla Permissions, Privileges, and Access Controls Vulnerability (CVE-2008-3226) Liferay DXP Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Vulnerability (CVE-2022-28982) WordPress Plugin Product Catalog Arbitrary File Upload (3.1.1) Joomla! Core 3.x.x Cross-Site Scripting (3.1.2 - 3.8.7) Severity Medium Classification CVE-2018-1042 CWE-918 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities