
Cloud Vulnerability DB
A community-led vulnerabilities database
A remote code execution vulnerability was identified in Moodle, tracked as CVE-2022-40314. The vulnerability affects Moodle versions 4.0 to 4.0.3, 3.11 to 3.11.9, 3.9 to 3.9.16, and earlier unsupported versions. The issue was discovered by Paul Holden and involves a security risk when restoring backup files originating from Moodle 1.9 (Moodle Forum, Red Hat Bugzilla).
The vulnerability is classified as serious and involves a remote code execution risk specifically when restoring backup files that originate from Moodle 1.9. The issue has been assigned a high severity rating, indicating its potential for significant impact (CERT-FR).
If exploited, this vulnerability could allow an attacker to execute arbitrary code remotely on the affected Moodle installation, potentially compromising the entire system (CERT-FR).
The vulnerability has been fixed in Moodle versions 4.0.4, 3.11.10, and 3.9.17. Users running affected versions should upgrade to these patched versions to mitigate the risk (Moodle Forum).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."