A flaw was found in Moodle before 3.7, 3.6.4, 3.5.6, 3.4.9 and 3.1.18. The form to upload cohorts contained a redirect field, which was not restricted to internal URLs.Referenceshttps://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-10133https://moodle.org/mod/forum/discuss.php?d=386523