Sceawere
Vulnerability Detail
CVE-2026-102577UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Moodle SSRF via Address Mapping
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 3h ago
- Vendor
- —
- Product
- N/A
- Attack Type
- Server-Side Request Forgery (SSRF)
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw was found in Moodle. Incorrect handling of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic allows an authenticated remote user to bypass blocked-host restrictions. By supplying a crafted URL, an attacker can induce the server to make requests to restricted destinations, leading to Server-Side Request Forgery (SSRF).
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-30T09:17:14.660Z",
"pubdate": "2026-09-30T09:17:14.660Z",
"executiveSummary": "A Server-Side Request Forgery (SSRF) vulnerability exists in Moodle due to improper validation of IPv4-mapped IPv6 addresses within the URL downloader's host-blocking logic.\nThe vulnerability allows an authenticated remote user to bypass established blacklist restrictions by obfuscating target host addresses using IPv6 mapping syntax.\nBy inducing the server to perform arbitrary outbound HTTP requests, an attacker can interact with internal network resources or services that are otherwise protected from external access.\nThis flaw impacts the Moodle URL downloader component. Successful exploitation requires an authenticated Moodle account with the ability to trigger URL downloads.\nThe primary risk involves the exposure of sensitive internal infrastructure, potential service disruption, or unauthorized access to internal metadata services and private APIs accessible to the web server.\nThis vulnerability highlights a critical failure in input sanitization and protocol-level address resolution within the security boundary of the downloader module.",
"technicalDetails": "The root cause of this vulnerability is an address parsing discrepancy between the URL downloader's security filter and the underlying network stack of the host server. The security mechanism designed to enforce host-blocking relies on a blacklist that is not equipped to normalize IPv4-mapped IPv6 addresses (e.g., ::ffff:127.0.0.1).\nWhen the Moodle URL downloader evaluates a URL, it performs a check to determine if the target hostname resolves to an unauthorized IP address or a loopback address. However, the logic fails to resolve or equate the IPv6-mapped representation to the actual IPv4 destination. Consequently, the filter permits the request to pass because the mapped address does not match the blocklist entries, even though the host system interprets the address as the internal resource upon connection.\nThe attack flow proceeds as follows: First, the attacker identifies a URL download feature within Moodle that accepts user-supplied input. Second, the attacker crafts a malicious request URL utilizing an IPv4-mapped IPv6 address to target a restricted internal endpoint, such as 'http://[::ffff:127.0.0.1]:80/' or an internal cloud metadata service. Third, the URL downloader's host-blocking logic evaluates the string, fails to recognize the address as a forbidden local or internal resource, and permits the downloader to proceed with the request.\nThe server, upon attempting to fetch the content from the provided URL, resolves the IPv4-mapped address to the internal destination. The server-side request is then executed against the target service, which treats the request as originating from the local web server itself. This bypasses network-level access controls and firewall rules that might otherwise restrict access to internal services.\nAuthentication is required to trigger the vulnerable functionality, limiting the attack vector to authenticated users. However, since many Moodle installations permit user registration or have low-privileged roles, this exposure is significant. The impact of successful exploitation includes potential unauthorized access to sensitive data, information disclosure regarding internal infrastructure, and the ability to port scan or probe internal network segments through the Moodle server's request context."
}