GHSA-5cvx-cwpx-9rjh
GitHub Security Advisory
Moodle Code Injection vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.3.0-beta
(fixed in 4.3.0-rc2)
Packagist
moodle/moodle
Affected versions:
4.2.0
(fixed in 4.2.3)
Packagist
moodle/moodle
Affected versions:
4.1.0
(fixed in 4.1.6)
Packagist
moodle/moodle
Affected versions:
4.0.0
(fixed in 4.0.11)
Packagist
moodle/moodle
Affected versions:
3.10.0
(fixed in 3.11.17)
Packagist
moodle/moodle
Affected versions:
0
(fixed in 3.9.24)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 14, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.