Description
In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
Remediation
References
Related Vulnerabilities
Jenkins Improper Input Validation Vulnerability (CVE-2018-1999002)
WebLogic CVE-2020-2546 Vulnerability (CVE-2020-2546)
Jboss EAP Uncontrolled Resource Consumption Vulnerability (CVE-2020-25689)
PHP Other Vulnerability (CVE-2015-6835)
WordPress Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2013-4338)