Re: Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
Oss-security thread discusses a Moodle 3.9.2 authenticated file-upload validation bypass (CWE-434) enabling RCE under misconfiguration.
An oss-security mailing list thread covers a reported Moodle LMS 3.9.2 authenticated file-upload validation bypass (CWE-434) that can lead to remote code execution when the platform is misconfigured. A reply from Alan Coopersmith notes that oss-security is not a CNA and cannot issue CVE IDs, citing pre-2017 policy discussion.
15