Back to Database
Status published
Unknown
CVE-2024-38275
moodle: HTTP authorization header is preserved between "emulated redirects"
Vulnerability Description
The cURL wrapper in Moodle retained the original request headers when following redirects, so HTTP authorization header information could be unintentionally sent in requests to redirect URLs.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-38275
Credits & Attribution
No credits recorded in the NVD database.
More from Moodle
View All →CVE-2025-53021
A session fixation vulnerability in Moodle 3.x through 3.11.18 allows...
Medium
4.2
CVE-2025-34032
Moodle LMS Jmol Plugin Cross-site Scripting (XSS)
Medium
5.1
CVE-2025-34031
Moodle LMS Jmol Plugin Path Traversal
High
8.7
CVE-2024-38277
moodle: QR login key and auto-login key for the Moodle mobile app should be generated as separate keys
Unknown
0
CVE-2024-38276
moodle: CSRF risks due to misuse of confirm_sesskey
Unknown
0
Affected Vendor
Moodle
View all reports →Affected Software
Moodle
Vulnerable Versions:
4.4, 4.3, 4.2, 4.1
Timeline
Official Publish:
June 18th, 2024
Last Modified:
August 2nd, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
No vector data available
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.