The referrer URL used by MFA required additional sanitizing, rather than being used directly.
During the MFA process, the application retrieved the referrer URL and used it directly in application logic, bypassing required sanitization steps. Lack of proper input validation (CWE-20) means that an attacker can provide a crafted referrer URL, which will be processed by the system in an unintended manner. Network vector (AV:N) without required privileges (PR:N) and user interaction (UI:N) indicates that the attack can be conducted remotely by an unauthenticated attacker.
Successful exploitation of the vulnerability may lead to violation of confidentiality, integrity, and availability of the system to a high degree — which corresponds to complete takeover of control over application resources or its users.
Patches available from the vendor should be applied in accordance with the references (https://moodle.org/mod/forum/discuss.php?d=458387). It is recommended to update to the patched version as soon as possible and monitor logs for suspicious Referer header values.
Moodle platform — versions indicated in vendor references
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HMoodle
APPMoodle4.3.0 – 4.3.4 (excl.)
Related vulnerabilities
Moodle: potencjalny Mustache injection w pomocniku Mustache pix
SQL Injection w Moodle — biblioteka pobierania kursów użytkownika
RCE w pluginie uwierzytelniania Shibboleth w Moodle
SQL injection w bibliotece pobierania ostatnich kursów użytkownika w Moodle
Blind SSRF w bibliotece LTI provider platformy Moodle