PT-2016-7686 · Moodle · Moodle

Published

2016-11-04

·

Updated

2016-11-29

·

CVE-2016-9186

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle version 3.1.2
Description The issue concerns an unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules. This allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension and then accessing it via unspecified vectors.
Recommendations For Moodle version 3.1.2, consider restricting access to the "legacy course files" and "file manager" modules to prevent exploitation until a fix is available. As a temporary workaround, restrict the ability to upload files with executable extensions in these modules.

Exploit

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-9186

Affected Products

Moodle