CVE-2018-1133

HIGH

Moodle 3.x - RCE

Title source: llm

Description

An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection.

Exploits (4)

exploitdb WORKING POC
by Darryn Ten · phpwebappsphp
https://www.exploit-db.com/exploits/46551
nomisec WORKING POC 10 stars
by darrynten · poc
https://github.com/darrynten/MoodleExploit
nomisec WORKING POC
by That-Guy-Steve · poc
https://github.com/That-Guy-Steve/CVE-2018-1133-Exploit
nomisec WORKING POC
by Feidao-fei · poc
https://github.com/Feidao-fei/MOODLE-3.X-Remote-Code-Execution

Scores

CVSS v3 8.8
EPSS 0.6447
EPSS Percentile 98.5%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-94
Status published
Products (2)
moodle/moodle 3.1 - 3.1.12Packagist
moodle/moodle 3.1.0 - 3.1.11
Published May 25, 2018
Tracked Since Feb 18, 2026