An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5458 | An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack. |
Github GHSA |
GHSA-vxqh-mx28-7ghw | Moodle Portfolio script allows instantiation of class chosen by user |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T03:51:48.791Z
Reserved: 2017-12-04T00:00:00
Link: CVE-2018-1137
No data.
Status : Modified
Published: 2018-05-25T12:29:00.403
Modified: 2024-11-21T03:59:16.063
Link: CVE-2018-1137
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA