CVE-2018-1043: Moodle
Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.
In Moodle 3.x, the setting for blocked hosts list can be bypassed with multiple A record hostnames.
Affected products
- Moodle Moodle: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.2.5 only; …
Published 2018-01-22. Last modified 2026-06-17.