CVE-2020-10738: Input Validation
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-10738?
CVE-2020-10738 is a vulnerability found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12, and earlier unsupported versions.
How can this vulnerability be exploited?
This vulnerability allows an attacker to interact with a SCORM package added to a course via web services, enabling remote attacks.
What is the severity of CVE-2020-10738?
The severity of CVE-2020-10738 is rated as high, with a severity score of 8.8.
Which versions of Moodle are affected?
Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12, and earlier unsupported versions are affected.
How can I fix CVE-2020-10738?
To fix CVE-2020-10738, upgrade to Moodle versions 3.8.3, 3.7.6, 3.6.10, or 3.5.12, depending on the affected version.