QID 997911

Date Published: 2024-04-03

QID 997911: PHP (Composer) Security Update for moodle/moodle (GHSA-c3pr-h96w-2jjg)

moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Refer to Github security advisory GHSA-c3pr-h96w-2jjg for updates and patch information.
    Vendor References

    CVEs related to QID 997911

    Software Advisories
    Advisory ID Software Component Link
    GHSA-c3pr-h96w-2jjg moodle/moodle URL Logo github.com/advisories/GHSA-c3pr-h96w-2jjg