CVE-2020-1755: Moodle

Medium severity, CVSS 5.3. EPSS: 0.5% chance of exploitation in the next 30 days.

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, X-Forwarded-For headers could be used to spoof a user's IP, in order to bypass remote address checks.

Affected products

  • Moodle Moodle: from 3.5.0, before 3.5.11 (fixed in 3.5.11); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.5 (fixed in 3.7.5); from 3.8.0, before 3.8.2 (fixed in 3.8.2)

Published 2022-08-16. Last modified 2026-06-17.