A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If a malicious backup file is restored, it could lead to unintended execution of server-side code. Since restore capabilities are typically available to privileged users, exploitation requires authenticated access. Successful exploitation could result in full compromise of the Moodle server.
{
"versions": [
{
"introduced": "0"
},
{
"fixed": "4.5.9"
},
{
"introduced": "5.0.0"
},
{
"fixed": "5.0.5"
},
{
"introduced": "5.1.0"
},
{
"fixed": "5.1.2"
}
]
}