Re: Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
AI summary · glm-5.3
Oss-security thread discusses a Moodle 3.9.2 authenticated file-upload validation bypass (CWE-434) enabling RCE under misconfiguration.
An oss-security mailing list thread covers a reported Moodle LMS 3.9.2 authenticated file-upload validation bypass (CWE-434) that can lead to remote code execution when the platform is misconfigured. A reply from Alan Coopersmith notes that oss-security is not a CNA and cannot issue CVE IDs, citing pre-2017 policy discussion.
- Moodle 3.9.2 authenticated upload bypass (CWE-434) yields RCE only under misconfiguration.
Full article
Posted by Alan Coopersmith on Sep 29 oss-security is not a CNA and cannot issue CVE IDs. Before 2017, the https://www.openwall.com/lists/oss-security/2017/02/09/7
This source does not provide full text. Read it at seclists.org.