Moodle Remote Code Execution... CVE-2017-2641 CNNVD-201703-961

7.5 AV AC AU C I A
发布: 2017-03-26
修订: 2017-08-16

The vulnerability (CVE-2017-2641) allows an attacker to execute PHP code at the vulnerable Moodle server. This vulnerability actually consists of many small vulnerabilities, as described further in the blog post. Moodle is a very popular learning management system, deployed in many universities around the world, including top institutes such as MIT, Stanford, the University of Cambridge, and Oxfords’ University. These statistics, along with the fact Moodle stores a lot of sensitive information, such as grades, tests, and students private data, makes it a critical target, and the main reason I audited it. A user is required to exploit the vulnerability. It does not matter which capabilities it has (i.e. student, teacher) as long as it is not a guest. This vulnerability works on almost all Moodle versions deployed today, as seen in the Vulnerable Versions section. I recommend all Moodle administrators to apply the [security...

0%
当前有1条漏洞利用/PoC
当前有52条受影响产品信息