Impact
A Moodle flaw allows an authenticated remote user to supply an IPv4‑mapped IPv6 address in a URL meant for the internal downloader. Because the downloader’s host‑blocking logic misinterprets such addresses, the server can be coerced into making requests to destinations that are normally blocked. This bypass produces a Server‑Side Request Forgery that can reach internal or restricted resources, exposing confidential data or permitting further lateral movement.
Affected Systems
All Moodle installations that use the URL downloader feature are potentially vulnerable, regardless of the version, since no version‑specific mitigation is listed. Administrators should confirm whether their instance incorporates the affected code base and review the URL downloader configuration.
Risk and Exploitability
The CVSS score of 4.3 rates this as a low‑severity flaw, but the requirement of authenticated access means that access to a site with user credentials is sufficient for exploitation. Exploitability is therefore limited to situations where an attacker can log in to the Moodle instance. No EPSS score is provided, and the vulnerability is not in the CISA KEV list, indicating that it is not known to be actively exploited at scale.
OpenCVE Enrichment