CVE-2024-38275: Moodle
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Affected products
- Moodle Moodle: before 4.1.11 (fixed in 4.1.11); from 4.2.0, before 4.2.8 (fixed in 4.2.8); from 4.3.0, before 4.3.5 (fixed in 4.3.5); version 4.4.0 only
Published 2024-06-18. Last modified 2026-06-17.