CVE-2018-1133: Code Injection
Published May 25, 2018
·Updated
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.
Affected Software
8 affected componentsFixes available
composer/moodle/moodle>=3.4<3.4.3
3.4.3
composer/moodle/moodle>=3.3<3.3.6
3.3.6
composer/moodle/moodle>=3.2<3.2.9
3.2.9
composer/moodle/moodle>=3.1<3.1.12
3.1.12
Moodle moodle>=3.1.0<=3.1.11
Moodle moodle>=3.2.0<=3.2.8
Moodle moodle>=3.3.0<=3.3.5
Moodle moodle>=3.4.0<=3.4.2
Remediation
Patch Available
Event History
May 25, 2018
CVE Published
via MITRE·12:00 PM
Data Sourced
via MITRE·12:00 PM
DescriptionWeakness
May 13, 2022
Advisory Published
via GitHub·01:18 AM
Frequently Asked Questions
1
What is the severity of CVE-2018-1133?
CVE-2018-1133 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2018-1133?
To fix CVE-2018-1133, upgrade to Moodle version 3.1.12, 3.2.9, 3.3.6, or 3.4.3.
3
Who is affected by CVE-2018-1133?
CVE-2018-1133 affects Moodle versions 3.1.x, 3.2.x, 3.3.x, and 3.4.x up to specified versions.
4
What causes CVE-2018-1133?
CVE-2018-1133 is caused by an eval injection vulnerability in the Calculated question feature of Moodle.
5
Can CVE-2018-1133 be exploited remotely?
Yes, CVE-2018-1133 can be exploited remotely by an attacker with teacher permissions to execute arbitrary code on the server.