Untriaged
Moodle: remote code execution via calculated question types
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
Affected products
moodle
- <4.2.9
- <4.1.12
- <4.3.6
- <4.4.2
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>