Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-14630

Опубликовано: 17 сент. 2018
Источник: nvd
CVSS3: 8.8
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия до 3.0.10 (включая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.1.0 (включая) до 3.1.14 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.3.0 (включая) до 3.3.8 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.4.0 (включая) до 3.4.5 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 3.5.0 (включая) до 3.5.2 (исключая)

EPSS

Процентиль: 82%
0.01792
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20
CWE-94

Связанные уязвимости

CVSS3: 8.8
ubuntu
почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

CVSS3: 8.8
debian
почти 7 лет назад

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an ...

CVSS3: 8.8
github
около 3 лет назад

Moodle XML import of ddwtos could lead to intentional remote code execution

EPSS

Процентиль: 82%
0.01792
Низкий

8.8 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-20
CWE-94