Remote Code Execution Vulnerability in Moodle by Moodle
CVE-2018-1137

8.1HIGH

Key Information:

Vendor

Moodle

Vendor
CVE Published:
25 May 2018

What is CVE-2018-1137?

An identified vulnerability in Moodle 3.x allows users to exploit URL manipulation in portfolios, leading to potential remote code execution. This issue can be leveraged by logged-in guests, who may initiate a distributed denial of service (DDoS) attack by instantiating arbitrary classes. Immediate remediation is advised to mitigate the risk associated with this vulnerability.

Affected Version(s)

Moodle 3.x unknown Moodle 3.x unknown

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.