{"id":"CVE-2018-1042","details":"Moodle 3.x has Server Side Request Forgery in the filepicker.","aliases":["GHSA-qqjv-mc2v-p7mc"],"modified":"2026-07-08T14:13:37.591547Z","published":"2018-01-22T08:29:00.240Z","references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/153766/Moodle-Filepicker-3.5.2-Server-Side-Request-Forgery.html"},{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/102752"},{"type":"ADVISORY","url":"https://moodle.org/mod/forum/discuss.php?d=364381"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/moodle/moodle","events":[{"introduced":"0"},{"last_affected":"687aad78bdf56bd5411185534ad3013c7b3f12ed"},{"introduced":"b182239f21c38ea57cddb41b0c03ef3eb02709f8"},{"last_affected":"665c3ac59c35b7387a4fc70b8ac6600ce9ffeb87"}],"database_specific":{"source":["CPE_RANGE","CPE_STRING"],"cpe":["cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.0:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.1:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.2:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.3:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.4:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.5:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.2.6:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.3.0:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.3.1:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.3.2:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.3.3:*:*:*:*:*:*:*","cpe:2.3:a:moodle:moodle:3.4.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0"},{"last_affected":"3.1.9"},{"introduced":"3.2.0"},{"last_affected":"3.2.0"},{"introduced":"3.2.1"},{"last_affected":"3.2.1"},{"introduced":"3.2.2"},{"last_affected":"3.2.2"},{"introduced":"3.2.3"},{"last_affected":"3.2.3"},{"introduced":"3.2.4"},{"last_affected":"3.2.4"},{"introduced":"3.2.5"},{"last_affected":"3.2.5"},{"introduced":"3.2.6"},{"last_affected":"3.2.6"},{"introduced":"3.3.0"},{"last_affected":"3.3.0"},{"introduced":"3.3.1"},{"last_affected":"3.3.1"},{"introduced":"3.3.2"},{"last_affected":"3.3.2"},{"introduced":"3.3.3"},{"last_affected":"3.3.3"},{"introduced":"3.4.0"},{"last_affected":"3.4.0"}]}}],"versions":["3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.3.0","3.3.1","3.3.2","3.3.3","3.4.0","v3.4.0","v3.1.9","v3.4.0-rc2","v3.4.0-rc3","v3.4.0-rc1","v3.4.0-beta","v3.1.8","v3.1.7","v3.1.6","v3.3.0","v3.3.0-rc3","v3.3.0-rc2","v3.3.0-rc1","v3.3.0-beta","v3.1.5","v3.1.4","v3.2.0","v3.1.3","v3.1.2","v3.1.1","v3.1.0-beta","v3.1.0","v3.1.0-rc2","v3.1.0-rc1","v3.0.0-rc3","v3.0.0","v3.0.0-rc4","v3.0.0-rc2","v3.0.0-rc1","v3.0.0-beta","v2.9.0","v2.9.0-rc2","v2.9.0-rc1","v2.9.0-beta","v2.8.0","v2.8.0-rc2","v2.8.0-rc1","v2.8.0-beta","v2.7.0","v2.7.0-rc2","v2.7.0-rc1","v2.7.0-beta","v2.6.0","v2.6.0-rc1","v2.6.0-beta","v2.5.0","v2.5.0-rc1","v2.5.0-beta","v2.4.0-beta","v2.4.0-rc1","v2.4.0","v2.3.0","v2.3.0-rc1","v2.3.0-beta","v2.2.0","v2.2.0-rc1","v2.2.0-beta","v2.1.0","v2.0.1","v2.0.0","v2.0.0-rc2","v2.0.0-rc1","v1.3.0","v1.2.1","v1.2.0","v1.1.1","v1.1.0","v1.0.9","v1.0.8","v1.0.7","v1.0.6","v1.0.5","v1.0.4","v1.0.3","v1.0.2","v1.0.1","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1042.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"}]}