moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to...
Vulnerability Description
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-14630
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.securityfocus.com/bid/105354
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-62880
- https://moodle.org/mod/forum/discuss.php?d=376023
- https://seclists.org/fulldisclosure/2018/Sep/28
- https://www.sec-consult.com/en/blog/advisories/remote-code-execution-php-unserialize-moodle-open-source-learning-platform-cve-2018-14630/
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14630
More from [UNKNOWN]
View All →Affected Vendor
[UNKNOWN]
View all reports →