BIT-moodle-2025-3642

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3642.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-moodle-2025-3642
Aliases
Published
2026-01-26T14:49:46.287Z
Modified
2026-01-26T17:41:08.968043Z
Summary
Moodle: authenticated remote code execution risk in the moodle lms equella repository
Details

A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.

Database specific
{
    "cpes": [
        "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / moodle

Package

Name
moodle
Purl
pkg:bitnami/moodle

Severity

  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.1.18
Introduced
4.3.0
Fixed
4.3.12
Introduced
4.4.0
Fixed
4.4.8
Introduced
4.5.0
Fixed
4.5.4

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/moodle/BIT-moodle-2025-3642.json"