
SSRF to XSS - XSS to RCE Moodle
This is a Proof of Concept (PoC) demonstrating the SSRF to XSS → XSS to RCE vulnerability chain in Moodle.
I’ve uploaded all the necessary files to demonstrate the full chain of exploitation:
Tested on Moodle version 4.4.5 (Build: 20241209).
Before proceeding, make sure to carefully review the files. You'll need to modify certain elements like your IP address.
For a step-by-step walkthrough, I’ve also uploaded a video demonstrating the exploit:
To mitigate this vulnerability:
Special thanks to p0dalirius, from whom I got the plugin used to upload and gain Remote Code Execution in Moodle.