Description
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
CVSS Metrics
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Vector
- network
- Complexity
- low
- Privileges
- low
- User Action
- none
- Scope
- unchanged
- Confidentiality
- high
- Integrity
- high
- Availability
- high
- Weaknesses
- CWE-94
Metadata
- Primary Vendor
- MOODLE
- Published
- 4/25/2025
- Last Modified
- 6/24/2025
- Source
- NIST NVD
- Note: Verify all details with official vendor sources before applying patches.
Affected Products
moodle : moodlemoodle : moodlemoodle : moodlemoodle : moodle
AI-Powered Remediation
Generate remediation guidance or a C-suite brief for this vulnerability.