A flaw was found in Moodle. An Open Redirect vulnerability in the OAuth login flow allows a remote attacker to redirect users to attacker-controlled pages after they have successfully authenticated. This occurs due to insufficient validation of redirect parameters, which could lead to phishing attacks or information disclosure.
{
"nvd_published_at": "2026-02-03T11:15:55Z",
"cwe_ids": [
"CWE-601"
],
"github_reviewed_at": "2026-02-03T19:07:08Z",
"severity": "LOW",
"github_reviewed": true
}