First published: Tue Sep 20 2022(Updated: )
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | >=3.9<3.9.17 | |
Moodle Moodle | >=3.11<3.11.10 | |
Moodle Moodle | >=4.0<4.0.4 | |
composer/moodle/moodle | >=4.0<4.0.4 | 4.0.4 |
composer/moodle/moodle | >=3.11<3.11.10 | 3.11.10 |
composer/moodle/moodle | <3.9.17 | 3.9.17 |
>=3.9<3.9.17 | ||
>=3.11<3.11.10 | ||
>=4.0<4.0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40314 is a vulnerability that allows remote code execution when restoring backup files originating from Moodle 1.9.
The affected software includes Moodle versions between 3.9.0 and 3.9.17, between 3.11.0 and 3.11.10, and between 4.0.0 and 4.0.4.
CVE-2022-40314 is classified as critical with a severity rating of 9.8.
To fix CVE-2022-40314, it is recommended to upgrade Moodle to a version that is not affected by the vulnerability.
More information about CVE-2022-40314 can be found at the following references: [Red Hat Security Advisory](https://access.redhat.com/security/cve/CVE-2022-40314), [Moodle Git Repository](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75405), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2128147)