VYPR
Medium severity5.3NVD Advisory· Published Apr 4, 2018· Updated Jun 17, 2026

CVE-2018-1081

CVE-2018-1081

Description

A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 3.1, < 3.1.113.1.11
moodle/moodlePackagist
>= 3.2, < 3.2.83.2.8
moodle/moodlePackagist
>= 3.3, < 3.3.53.3.5
moodle/moodlePackagist
>= 3.4, < 3.4.23.4.2

Affected products

3
  • cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
    Range: <=3.0.10
  • ghsa-coords
    Range: >= 3.1, < 3.1.11
  • Red Hat, Inc./Moodlev5
    Range: 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.