CVE-2018-14630
Moodle XML import of ddwtos could lead to intentional remote code execution
8.8
HIGH
CVSS 3.1
EPSS 1.9%
Description
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.
How to fix CVE-2018-14630
To remediate CVE-2018-14630, upgrade the affected package to a fixed version below.
- —upgrade to 3.5.2 or later
Is CVE-2018-14630 being exploited?
Low — EPSS is 1.9%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 3.5.0, < 3.5.2
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH8.8 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |