Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qfh6-h7j6-fvjv

Опубликовано: 03 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Moodle formula injection vulnerability

A flaw was found in Moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.1.22

4.1.22

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.4.0-beta, < 4.4.12

4.4.12

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.8

4.5.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.4

5.0.4

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.1.0-beta, < 5.1.1

5.1.1

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1236

Связанные уязвимости

CVSS3: 6.1
ubuntu
5 дней назад

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

CVSS3: 6.1
nvd
5 дней назад

A flaw was found in moodle. This formula injection vulnerability occurs when data fields are exported without proper escaping. A remote attacker could exploit this by providing malicious data that, when exported and opened in a spreadsheet, allows arbitrary formulas to execute. This can lead to compromised data integrity and unintended operations within the spreadsheet.

CVSS3: 6.1
debian
5 дней назад

A flaw was found in moodle. This formula injection vulnerability occur ...

EPSS

Процентиль: 10%
0.00035
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-1236