Remote Code Execution Vulnerability in Moodle by Moodle
CVE-2018-1137
8.1HIGH
What is CVE-2018-1137?
An identified vulnerability in Moodle 3.x allows users to exploit URL manipulation in portfolios, leading to potential remote code execution. This issue can be leveraged by logged-in guests, who may initiate a distributed denial of service (DDoS) attack by instantiating arbitrary classes. Immediate remediation is advised to mitigate the risk associated with this vulnerability.
Affected Version(s)
Moodle 3.x unknown Moodle 3.x unknown