VYPR
Critical severityNVD Advisory· Published Nov 25, 2022· Updated Apr 29, 2025

CVE-2022-45152

CVE-2022-45152

Description

A blind Server-Side Request Forgery (SSRF) vulnerability was found in Moodle. This flaw exists due to insufficient validation of user-supplied input in LTI provider library. The library does not utilise Moodle's inbuilt cURL helper, which resulted in a blind SSRF risk. An attacker can send a specially crafted HTTP request and trick the application to initiate requests to arbitrary systems. This vulnerability allows a remote attacker to perform SSRF attacks.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
moodle/moodlePackagist
>= 3.9, < 3.9.183.9.18
moodle/moodlePackagist
>= 3.11, < 3.11.113.11.11
moodle/moodlePackagist
>= 4.0, < 4.0.54.0.5

Affected products

3

Patches

Vulnerability mechanics

References

13

News mentions

0

No linked articles in our index yet.