Description
A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.
Remediation
References
Related Vulnerabilities
WordPress Plugin User Submitted Posts Arbitrary File Upload (20190426)
WordPress Plugin Video Chat Multiple Cross-Site Scripting Vulnerabilities (1.4.1)
WordPress Plugin VaultPress Man-in-The-Middle (MiTM) Remote Code Execution (1.8.6)
ownCloud Permissions, Privileges, and Access Controls Vulnerability (CVE-2013-2047)