Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-26046

Опубликовано: 21 фев. 2026
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия до 4.5.9 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 5.0.0 (включая) до 5.0.5 (исключая)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
Версия от 5.1.0 (включая) до 5.1.2 (исключая)

EPSS

Процентиль: 81%
0.02202
Низкий

7.2 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 7.2
ubuntu
5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
debian
5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative settin ...

CVSS3: 7.2
github
5 месяцев назад

A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.

CVSS3: 7.2
fstec
5 месяцев назад

Уязвимость виртуальной обучающей среды Moodle, связанная с непринятием мер по нейтрализации специальных элементов, позволяющая нарушителю выполнить произвольные команды

CVSS3: 7.2
redos
3 месяца назад

Уязвимость moodle

EPSS

Процентиль: 81%
0.02202
Низкий

7.2 High

CVSS3

Дефекты

CWE-78