Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c3pr-h96w-2jjg

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Moodle XML import of ddwtos could lead to intentional remote code execution

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5.0, < 3.5.2

3.5.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.4.0, < 3.4.5

3.4.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.2.0, < 3.3.8

3.3.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 3.1.14

3.1.14

EPSS

Процентиль: 82%
0.01792
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
nvd
почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
debian
почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

EPSS

Процентиль: 82%
0.01792
Низкий

8.8 High

CVSS3

Дефекты

CWE-94