PT-2022-5130 · Moodle+2 · Moodle+2
Paul Holden
·
Published
2020-11-08
·
Updated
2025-05-20
·
CVE-2022-40314
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moodle versions 1.9
Description
A remote code execution risk exists when restoring backup files. The issue is related to insecure input validation during the restoration process. Exploitation of this issue may allow a remote attacker to execute arbitrary code by uploading a restored file. This can also lead to an attacker tricking a victim into restoring a website from a tampered backup, resulting in code execution on the target system.
Recommendations
For Moodle version 1.9, update to a version that includes a fix for this issue to prevent remote code execution risks when restoring backup files.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Deserialization of Untrusted Data
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Moodle
Red Os