Описание
Moodle calculated question type allows remote code execution by Question authors
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
Пакеты
moodle/moodle
>= 3.1, < 3.1.12
3.1.12
moodle/moodle
>= 3.2, < 3.2.9
3.2.9
moodle/moodle
>= 3.3, < 3.3.6
3.3.6
moodle/moodle
>= 3.4, < 3.4.3
3.4.3
Связанные уязвимости
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated ...