8.8 HIGH
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): LOW
- User interaction (UI): NONE
- Scope (S): UNCHANGED
- Confidentiality impact (C): HIGH
- Integrity impact (I): HIGH
- Availability impact (A): HIGH
Moodle: authenticated remote code execution risk in the moodle lms dropbox repository
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
References
- https://access.redhat.com/security/cve/CVE-2025-3641 x_refsource_REDHAT vdb-entry
- RHBZ#2359735 issue-tracking x_refsource_REDHAT
- https://moodle.org/mod/forum/discuss.php?d=467602
- https://access.redhat.com/security/cve/CVE-2025-3641 x_refsource_REDHAT vdb-entry
- RHBZ#2359735 issue-tracking x_refsource_REDHAT
- https://moodle.org/mod/forum/discuss.php?d=467602
Affected products
- <4.1.18
- <4.5.4
- <4.3.12
- <4.4.8
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>