In Moodle, insufficient redirect handling made it possible to blindly bypass cURL blocked hosts/allowed ports restrictions, resulting in a blind SSRF risk.
A flaw was found in moodle where global search results could include author information on some activities where a user may not otherwise have access to it.