Moodle vulnerable to PHP object injection attacks
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 2, 2024
Package
Affected versions
< 2.4.11
>= 2.5.0, < 2.5.7
>= 2.6.0, < 2.6.4
>= 2.7.0, < 2.7.1
Patched versions
2.4.11
2.5.7
2.6.4
2.7.1
Description
Published by the National Vulnerability Database
Jul 29, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 24, 2024
Last updated
Feb 2, 2024
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.
References