An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
2018-05-25T12:29:00.230
2024-11-21T03:59:15.633
Modified
CVSSv3.0: 8.8 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | ≤ 3.1.11 | Yes |
Application | moodle | moodle | ≤ 3.2.8 | Yes |
Application | moodle | moodle | ≤ 3.3.5 | Yes |
Application | moodle | moodle | ≤ 3.4.2 | Yes |