Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ggxq-2mg9-8966

Опубликовано: 21 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Moodle has a Remote Code Execution risk via file restore

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.1.0-beta, < 5.1.2

5.1.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.5

5.0.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.5.9

4.5.9

EPSS

Процентиль: 43%
0.00553
Низкий

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
nvd
5 месяцев назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
debian
5 месяцев назад

A flaw was identified in Moodle\u2019s backup restore functionality wh ...

CVSS3: 7.2
fstec
5 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.2
redos
30 дней назад

Уязвимость libsoup

EPSS

Процентиль: 43%
0.00553
Низкий

7.2 High

CVSS3

Дефекты

CWE-94