CVE-2024-38275 Information
Jun 19, 2024
cve
Description
The cURL wrapper in Moodle retained the original request headers when following redirects so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Reference
https://moodle.org/mod/forum/discuss.php?d=459500
Share on: