vendor:
Moodle
by:
Fabian Mosch & Nick Theisinger (r-tec IT Security GmbH)
6.5
CVSS
MEDIUM
Server Side Request Forgery
922
CWE
Product Name: Moodle
Affected Version From: Moodle Versions 3.4, 3.3, 3.3.3, 3.2 to 3.2.6, 3.1 to 3.1.9 and 3.5.2
Affected Version To: Moodle Version 3.5.2
Patch Exists: YES
Related CWE: CVE-2018-1042
CPE: a:moodle:moodle
Other Scripts:
N/A
Platforms Tested: Moodle Version 3.5.2
2019
Server Side Request Forgery in Moodle Filepicker
An authenticated attacker can scan the internal network and exploit internal web services with blind injections. In version 3.5.2, only pictures (PNG, GIF, SVN and so on) were displayed as a JSON-list. But it is possible to do internal port scans via http:// and https:// protocols. Open ports with no response for HTTP requests resulted in a timeout, SSL services like OpenSSH gave an SSL Error. For web applications the HTTP headers can be found in the response (403 forbidden, 404 not Found and so on). Found web applications can be attacked via HTTP GET requests. The vulnerable script is "repository_ajax.php" and the parameter is "file".
Mitigation:
Update to the latest version of Moodle, which is 3.5.3.