CVE-2012-6101 Information

Description

Multiple open redirect vulnerabilities in Moodle 2.2.x before 2.2.7 2.3.x before 2.3.4 and 2.4.x before 2.4.1 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors related to (1) backup/backupfilesedit.php (2) comment/comment_post.php (3) course/switchrole.php (4) mod/wiki/filesedit.php (5) tag/coursetags_add.php or (6) user/files.php.

Reference

http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-35991 http://openwall.com/lists/oss-security/2013/01/21/1 https://moodle.org/mod/forum/discuss.php?d=220162

Share on: