PT-2024-5807 · Moodle+2 · Moodle+2
Published
2024-08-27
·
Updated
2025-07-02
·
CVE-2024-43425
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moodle versions prior to 4.4.2
Moodle versions prior to 4.3.6
Moodle versions prior to 4.2.9
Moodle versions prior to 4.1.12
Description
A flaw was found in Moodle, allowing remote code execution due to incomplete sanitization in the calculated question types feature. This requires the capability to add or update questions. Attackers can execute arbitrary code, potentially disclosing students' confidential information or disrupting the learning process. An estimated 238,205 exposed Moodle instances have been detected, and the issue has been exploited in the wild.
Recommendations
For versions prior to 4.4.2, update to version 4.4.2 or later.
For versions prior to 4.3.6, update to version 4.3.6 or later.
For versions prior to 4.2.9, update to version 4.2.9 or later.
For versions prior to 4.1.12, update to version 4.1.12 or later.
As a temporary workaround, consider restricting access to the calculated questions feature until a patch is applied.
Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Moodle
Red Os