It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2021-01-28T18:30:03

Updated: 2024-08-03T17:30:07.535Z

Reserved: 2020-12-17T00:00:00

Link: CVE-2021-20187

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2021-01-28T19:15:13.377

Modified: 2022-10-21T20:09:46.700

Link: CVE-2021-20187

cve-icon Redhat

No data.