Description Moodle 3.x has Server Side Request Forgery in the filepicker. Remediation References CVE-2018-1042 Related Vulnerabilities Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2014-3542) PHP Address Book Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2009-2608) MySQL CVE-2019-2803 Vulnerability (CVE-2019-2803) WordPress Plugin Church Admin Arbitrary File Upload (1.2530) MediaWiki Improper Input Validation Vulnerability (CVE-2011-0003) Severity Medium Classification CVE-2018-1042 CWE-918 CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N Tags Missing Update Known Vulnerabilities