Remote Code Execution Vulnerability in Moodle by Moodle
CVE-2020-10738
7.5HIGH
What is CVE-2020-10738?
A security vulnerability present in multiple versions of Moodle allowed an attacker to create manipulated SCORM packages that, when integrated into courses, could interact through web services to execute arbitrary code remotely. This flaw affected several versions, including Moodle 3.8, 3.7, 3.6, and 3.5, as well as older, unsupported versions.
Affected Version(s)
moodle 3.8 to 3.8.2
moodle 3.7 to 3.7.5
moodle 3.6 to 3.6.9