-
CVSS Score
-The exploit demonstrates RCE through calculated question answer fields containing backtick-enclosed PHP code. The vulnerability pattern matches improper handling of user-controlled input in formula evaluation:
$_GET[0] with backticks| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 3.1, < 3.1.12 | 3.1.12 |
| moodle/moodle | composer | >= 3.2, < 3.2.9 | 3.2.9 |
| moodle/moodle | composer | >= 3.3, < 3.3.6 | 3.3.6 |
| moodle/moodle | composer | >= 3.4, < 3.4.3 | 3.4.3 |