Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ggxq-2mg9-8966

Опубликовано: 21 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 7.2

Описание

Moodle has a Remote Code Execution risk via file restore

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.1.0-beta, < 5.1.2

5.1.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.5

5.0.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.5.9

4.5.9

EPSS

Процентиль: 26%
0.00094
Низкий

7.2 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 7.2
ubuntu
около 1 месяца назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
nvd
около 1 месяца назад

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.

CVSS3: 7.2
debian
около 1 месяца назад

A flaw was identified in Moodle\u2019s backup restore functionality wh ...

EPSS

Процентиль: 26%
0.00094
Низкий

7.2 High

CVSS3

Дефекты

CWE-94