Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
I. Basic Information for CVE-2024-43425
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Moodle: remote code execution via calculated question types
Source: NVD (National Vulnerability Database)
Vulnerability Description
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Moodle 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Moodle是Moodle开源的一套免费的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle存在安全漏洞,该漏洞源于需要额外的限制来避免计算问题类型中的远程代码执行风险。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
II. Public POCs for CVE-2024-43425
#POC DescriptionSource LinkShenlong Link
1Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)https://github.com/RedTeamPentesting/moodle-rce-calculatedquestionsPOC Details
2Nonehttps://github.com/Snizi/Moodle-CVE-2024-43425-ExploitPOC Details
3Attackers with the permission to create or modify questions in Moodle courses are able to craft malicious inputs for calculated questions, which can be abused to execute arbitrary commands on the underlying system. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-43425.yamlPOC Details
4Nonehttps://github.com/aninfosec/CVE-2024-43425-PocPOC Details
5🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡https://github.com/aayush256-sys/Moodle-authenticated-RCEPOC Details
6Nonehttps://github.com/Tnot123/cve-2024-43425POC Details
7🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡https://github.com/kazuya256/Moodle-authenticated-RCEPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-43425
Please Login to view more intelligence information
V. Comments for CVE-2024-43425

No comments yet


Leave a comment