MEDIUM
course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter
Published Sep 23, 2006
5.0
MEDIUMCVSS 2.0
EPSS 1.23%
Description
Affected products
Remediation
Metrics
References (1)
Change history (0)
No recorded changes yet.