Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vr6v-g96p-cjc3

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Moodle vulnerable to RCE

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.8, <= 3.8.2

3.8.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.7, <= 3.7.5

3.7.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.6, <= 3.6.9

3.6.10

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.5, <= 3.5.11

3.5.12

EPSS

Процентиль: 84%
0.0234
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 5 лет назад

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.

CVSS3: 7.5
nvd
около 5 лет назад

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.

CVSS3: 7.5
debian
около 5 лет назад

A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6 ...

EPSS

Процентиль: 84%
0.0234
Низкий

8.8 High

CVSS3

Дефекты

CWE-20