VYPR
Unrated severityNVD Advisory· Published Sep 23, 2006· Updated Jun 16, 2026

CVE-2006-4943

CVE-2006-4943

Description

course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter.

Affected products

3
  • Moodle/Moodle3 versions
    cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*range: <=1.6.1
    • cpe:2.3:a:moodle:moodle:1.6.0:*:*:*:*:*:*:*
    • (no CPE)range: <1.6.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.