BIT-moodle-2025-3641

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3641.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-moodle-2025-3641
Aliases
Published
2026-01-26T14:49:44.921Z
Modified
2026-01-26T17:41:05.611837Z
Summary
Moodle: authenticated remote code execution risk in the moodle lms dropbox repository
Details

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.

Database specific
{
    "severity": "High",
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ]
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.18
Introduced
4.3.0
Fixed
4.3.12
Introduced
4.4.0
Fixed
4.4.8
Introduced
4.5.0
Fixed
4.5.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3641.json"