PT-2016-7686 · Moodle · Moodle
Publicado
2016-11-04
·
Atualizado
2016-11-29
·
CVE-2016-9186
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moodle version 3.1.2
Description
The issue concerns an unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules. This allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and then accessing it via unspecified vectors.
Recommendations
For Moodle version 3.1.2, consider restricting access to the "legacy course files" and "file manager" modules to prevent exploitation until a fix is available. As a temporary workaround, restrict the ability to upload files with executable extensions in these modules.
Exploit
Correção
Unrestricted File Upload
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Moodle