It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
2021-01-28T19:15:13.377
2024-11-21T05:46:05.707
Modified
CVSSv3.1: 7.2 (HIGH)
AV:N/AC:L/Au:S/C:P/I:P/A:P
8.0
6.4
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 3.5.16 | Yes |
Application | moodle | moodle | < 3.8.7 | Yes |
Application | moodle | moodle | < 3.9.4 | Yes |
Application | moodle | moodle | 3.10.0 | Yes |