ZeroHour

CVE-2024-43425

mass

Code injection RCE risk in Moodle calculated question types

CVSS 3.1
8.1 high
EPSS
83%p100
Published
()
Modified
AI analysis

CVE-2024-43425 is a code-injection flaw (CWE-94) in Moodle's calculated question types, where insufficiently restricted evaluation of question formulas leaves a remote code execution risk on the web server. It is triggered when a user with the capability to add or update questions — typically a teacher, editing teacher or manager role — submits a crafted calculated question, and it is exploited when the question engine evaluates the injected code. A successful attacker gains remote code execution with the privileges of the Moodle web-server process, consistent with the high confidentiality, integrity and availability impacts behind its 8.1 CVSS 3.1 score (network vector; the advisory note clarifies it requires question-authoring capability, so anonymous visitors cannot trigger it directly). All unpatched Moodle deployments are in scope because question-editing capability is routinely granted to teaching staff. No public proof-of-concept or confirmed in-the-wild exploitation is known and it is not in CISA KEV, but EPSS assigns an 83.1% probability of exploitation within 30 days (100th percentile), making prompt patching urgent.

What to do: Upgrade Moodle to 4.4.3, 4.3.6 or 4.2.9 (or any later release from October 2024 onward) in line with Moodle's advisory. Until patched, restrict the capability to add/update questions to trusted staff — the practical mitigation — and audit recently created or edited calculated questions, especially on sites where lower-trust users (e.g., non-editing teachers or shared course banks) can author questions. With no known public exploit, patching before the high EPSS probability materializes into in-the-wild activity should be the priority.

Affected
MoodleSupported branches 4.4 (up to 4.4.2), 4.3 (up to 4.3.5) and 4.2 (up to 4.2.8), plus earlier unsupported versions, per Moodle's security advisory; fixed in 4.4.3
Estimated exposure
masstens of thousands of Moodle sites worldwide (~80,000+ registered sites; hundreds of millions of users) — Moodle's public usage statistics and LMS market-share data put the platform at roughly 80,000 registered sites and hundreds of millions of users, and virtually every deployment grants question-editing capability to teaching staff, so all…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

Vendors
moodle
Products
moodle
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.