Moodle vulnerable to RCE
High severity
GitHub Reviewed
Published
May 24, 2022
to the GitHub Advisory Database
•
Updated Aug 21, 2023
Package
Affected versions
>= 3.8, <= 3.8.2
>= 3.7, <= 3.7.5
>= 3.6, <= 3.6.9
>= 3.5, <= 3.5.11
Patched versions
3.8.3
3.7.6
3.6.10
3.5.12
Description
Published by the National Vulnerability Database
May 21, 2020
Published to the GitHub Advisory Database
May 24, 2022
Reviewed
Jul 13, 2023
Last updated
Aug 21, 2023
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
References