CVE-2018-1042
28Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 16%
from disclosure to weapon550 days
Published on NVDJan 22
1st PoC+550d
exploitation probability
16%top 3% of all CVEs
observed exploitation
nono source reports it
3 public exploit(s)
Moodle 3.x has Server Side Request Forgery in the filepicker.
Affected products
n/a · Moodle 3.xpublic PoCs found — 3
exploitdbwww.exploit-db.com/exploits/47177unverifiedgithubgithub.com/UDPsycho/Moodle-CVE-2018-1042★ 2cve_referencepacketstormsecurity.com/files/153766/Moodle-Filepicker-3.5.2-Server-Side-Request-Forgery.htmlunverified⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.