A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle
Published Nov 25, 2022
9.1
CRITICALCVSS 3.1
EPSS 1.44%
Description
A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.
Affected products
- Vendor n/a Product Moodle Defaultn/a
- Version Fixed in moodle 4.0.5, moodle 3.11.11, moodle 3.9.18StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | Moodle | n/a |
|
Configuration 1
Configuration 2
- 7.0
- 35
- 36
- 37
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Apr 29, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 3, 2026.
Score over time
2022-2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (15 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 3, 2026 | 1.44% (0.01441) | 72.30th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.35% (0.01352) | 67.80th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.27% (0.00268) | 48.26th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.30% (0.00300) | 70.36th | v3 (v2023.03.01) |
| Jun 17, 2024 | 0.30% (0.00300) | 69.65th | v3 (v2023.03.01) |
| May 7, 2024 | 0.29% (0.00286) | 68.62th | v3 (v2023.03.01) |
| Mar 1, 2024 | 0.20% (0.00204) | 57.56th | v3 (v2023.03.01) |
| Dec 2, 2023 | 0.18% (0.00179) | 54.87th | v3 (v2023.03.01) |
| Nov 8, 2023 | 0.10% (0.00105) | 42.59th | v3 (v2023.03.01) |
| Oct 26, 2023 | 0.15% (0.00150) | 50.86th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.13% (0.00133) | 46.65th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.32% (0.01319) | 71.27th | v2 (v2022.01.01) |
| Dec 7, 2022 | 1.32% (0.01319) | 70.73th | v2 (v2022.01.01) |
| Dec 2, 2022 | 1.14% (0.01136) | 58.49th | v2 (v2022.01.01) |
| Nov 26, 2022 | 1.06% (0.01061) | 51.68th | v2 (v2022.01.01) |
References (11)
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-71920
- https://bugzilla.redhat.com/show_bug.cgi?id=2142775
- https://github.com/advisories/GHSA-xqcf-vgqc-pcmg Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/2DHYIIAUXUBHMBEDYU7TYNZXEN2W2SA2 vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/74SXNGA5RIWM7QNX7H3G7SYIQLP4UUGV vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NLRJB5JNKK3VVBLV3NH3RI7COEDAXSAB vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/2DHYIIAUXUBHMBEDYU7TYNZXEN2W2SA2
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/74SXNGA5RIWM7QNX7H3G7SYIQLP4UUGV
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/NLRJB5JNKK3VVBLV3NH3RI7COEDAXSAB
- https://moodle.org/mod/forum/discuss.php?d=440772
- https://nvd.nist.gov/vuln/detail/CVE-2022-45152
Change history (0)
No recorded changes yet.