CVE-2018-14630: Code Injection
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within the imported questions, either intentionally or by importing questions from an untrusted source.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-14630?
CVE-2018-14630 has a critical severity as it allows for remote code execution through PHP code injection.
How do I fix CVE-2018-14630?
To fix CVE-2018-14630, upgrade Moodle to version 3.1.14, 3.3.8, 3.4.5, or 3.5.2 or later.
Which versions of Moodle are affected by CVE-2018-14630?
Moodle versions prior to 3.1.14, 3.3.8, 3.4.5, and 3.5.2 are affected by CVE-2018-14630.
What type of vulnerability is CVE-2018-14630?
CVE-2018-14630 is a remote code execution vulnerability that arises during XML imports of quiz questions.
Can CVE-2018-14630 be exploited by anyone?
Yes, CVE-2018-14630 can potentially be exploited by any authenticated user who can import ddwtos formatted quiz questions.