vulnerability

Moodle: Incomplete Cleanup (CVE-2024-38275)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Jun 18, 2024
Added
May 5, 2025
Modified
Aug 1, 2025

Description

The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.

Solutions

moodle-upgrade-4_1_11moodle-upgrade-4_2_8moodle-upgrade-4_3_5
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.