-
CVSS Score
-The vulnerability stems from improper handling of serialized user preferences containing malicious objects. The exploit chain involves:
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 2.7, < 2.7.19 | 2.7.19 |
| moodle/moodle | composer | >= 3.0, < 3.0.9 | 3.0.9 |
| moodle/moodle | composer | >= 3.1, < 3.1.5 | 3.1.5 |
| moodle/moodle | composer | >= 3.2, < 3.2.2 | 3.2.2 |