Moodle 4.3 insecure direct object reference Vulnerability / Exploit
/
/
/
Exploits / Vulnerability Discovered : 2024-02-27 |
Type : webapps |
Platform : php
This exploit / vulnerability Moodle 4.3 insecure direct object reference is for educational purposes only and if it is used you will do on your own risk!
1. Log in to the application with the given credentials > USER: teacher PASS: moodle
2. In profile.php?id=11, modify the id Parameter to View User details,
Email address, Country, City/town, City, Timezone
3. Change the existing "id" value to another number