CVE-2016-9187: Malicious File Upload
Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9187?
CVE-2016-9187 is considered a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2016-9187?
To fix CVE-2016-9187, upgrade Moodle to version 3.2.1 or later which addresses this vulnerability.
Who is affected by CVE-2016-9187?
CVE-2016-9187 affects Moodle versions up to and including 3.1.2, allowing unauthorized file uploads by authenticated users.
What can happen if CVE-2016-9187 is exploited?
If exploited, CVE-2016-9187 allows attackers to execute arbitrary code on the server by uploading malicious files.
What type of vulnerability is CVE-2016-9187?
CVE-2016-9187 is an unrestricted file upload vulnerability that occurs within the image module of Moodle.