RULE(RULE ID:336651)

Rule General Information
Release Date: 2022-06-21
Rule Name: Moodle CMS questiontype.php Answer Remote Code Execution Vulnerability (CVE-2018-1133)
Severity:
CVE ID:
Rule Protection Details
Description: An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: SecurityFocusBID:104307
ExploitDB:46551
https://moodle.org/mod/forum/discuss.php?d=371199
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://moodle.org/mod/forum/discuss.php?d=371199