VulnerabilityModified
CVE-2018-1137
An issue was discovered in Moodle 3.x.
HIGH 8.1EPSS 1.65%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.65%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
- EPSS
- 1.65% probability · 75th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- moodle/moodle
- Source
- secalert@redhat.com
References
- http://www.securityfocus.com/bid/104307Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=371204Vendor Advisory
- http://www.securityfocus.com/bid/104307Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=371204Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.