First published: Thu May 21 2020(Updated: )
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.5<=3.5.11 | 3.5.12 |
composer/moodle/moodle | >=3.6<=3.6.9 | 3.6.10 |
composer/moodle/moodle | >=3.7<=3.7.5 | 3.7.6 |
composer/moodle/moodle | >=3.8<=3.8.2 | 3.8.3 |
Moodle Moodle | >=3.5<3.5.12 | |
Moodle Moodle | >=3.6<3.6.10 | |
Moodle Moodle | >=3.7<3.7.6 | |
Moodle Moodle | >=3.8<3.8.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10738 is a vulnerability found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12, and earlier unsupported versions.
This vulnerability allows an attacker to interact with a SCORM package added to a course via web services, enabling remote attacks.
The severity of CVE-2020-10738 is rated as high, with a severity score of 8.8.
Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12, and earlier unsupported versions are affected.
To fix CVE-2020-10738, upgrade to Moodle versions 3.8.3, 3.7.6, 3.6.10, or 3.5.12, depending on the affected version.