An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-5458 An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
Github GHSA Github GHSA GHSA-vxqh-mx28-7ghw Moodle Portfolio script allows instantiation of class chosen by user
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2024-08-05T03:51:48.791Z

Reserved: 2017-12-04T00:00:00

Link: CVE-2018-1137

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-25T12:29:00.403

Modified: 2024-11-21T03:59:16.063

Link: CVE-2018-1137

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.