Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving an error page that links to a URL from an HTTP Referer header.
https://moodle.org/mod/forum/discuss.php?d=313682
http://www.securitytracker.com/id/1032358
http://www.securityfocus.com/bid/74720
http://openwall.com/lists/oss-security/2015/05/18/1
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-49179