PT-2016-7686 · Moodle · Moodle

Publicado

2016-11-04

·

Atualizado

2016-11-29

·

CVE-2016-9186

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle version 3.1.2
Description The issue concerns an unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules. This allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and then accessing it via unspecified vectors.
Recommendations For Moodle version 3.1.2, consider restricting access to the "legacy course files" and "file manager" modules to prevent exploitation until a fix is available. As a temporary workaround, restrict the ability to upload files with executable extensions in these modules.

Exploit

Correção

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-9186

Produtos afetados

Moodle