PT-2016-7686 · Moodle · Moodle
Published
2016-11-04
·
Updated
2016-11-29
·
CVE-2016-9186
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Moodle version 3.1.2
Description
The issue concerns an unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules. This allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and then accessing it via unspecified vectors.
Recommendations
For Moodle version 3.1.2, consider restricting access to the "legacy course files" and "file manager" modules to prevent exploitation until a fix is available. As a temporary workaround, restrict the ability to upload files with executable extensions in these modules.
Exploit
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Moodle