CVE-2024-43425
massCode injection RCE risk in Moodle calculated question types
CVE-2024-43425 is a code-injection flaw (CWE-94) in Moodle's calculated question types, where insufficiently restricted evaluation of question formulas leaves a remote code execution risk on the web server. It is triggered when a user with the capability to add or update questions — typically a teacher, editing teacher or manager role — submits a crafted calculated question, and it is exploited when the question engine evaluates the injected code. A successful attacker gains remote code execution with the privileges of the Moodle web-server process, consistent with the high confidentiality, integrity and availability impacts behind its 8.1 CVSS 3.1 score (network vector; the advisory note clarifies it requires question-authoring capability, so anonymous visitors cannot trigger it directly). All unpatched Moodle deployments are in scope because question-editing capability is routinely granted to teaching staff. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but EPSS assigns an 83.1% probability of exploitation within 30 days (100th percentile), making prompt patching urgent.
What to do: Upgrade Moodle to 4.4.3, 4.3.6 or 4.2.9 (or any later release from October 2024 onward) in line with Moodle's advisory. Until patched, restrict the capability to add/update questions to trusted staff — the practical mitigation — and audit recently created or edited calculated questions, especially on sites where lower-trust users (e.g., non-editing teachers or shared course banks) can author questions. With no known public exploit, patching before the high EPSS probability materializes into in-the-wild activity should be the priority.
| Moodle | Supported branches 4.4 (up to 4.4.2), 4.3 (up to 4.3.5) and 4.2 (up to 4.2.8), plus earlier unsupported versions, per Moodle's security advisory; fixed in 4.4.3 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
- Vendors
- moodle
- Products
- moodle
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.