Re: Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
Maintainers will not fix a Moodle 3.9.2 upload bypass to RCE unless current LTS versions are affected.
An oss-security reply discusses a reported authenticated file-upload validation bypass (CWE-434) in Moodle LMS 3.9.2 that could lead to remote code execution under misconfiguration. The poster says security bug fixes for the 3.9.x line ended on 11 December 2023, while newer 5.x releases exist and Moodle 5.4 LTS was expected within the week. They state no fix will be issued unless the issue is reproducible on a supported long-term support version.
- Authenticated file-upload validation bypass reported in Moodle LMS 3.9.2.
- Title says misconfiguration could turn the bypass into RCE.
- Security fixes for Moodle 3.9.x ended on 11 December 2023.
- No fix planned unless current LTS releases are affected.
Posted by Daniel Ziegenberg on Sep 30 Hi! https://moodledev.io/general/releases), and there are three other newer releases in the 5.x line. The next Moodle LTS, 5.4, will be released this coming week. If it's not reproducible in either of those two LTS versions, there will be no fix, as there are plenty of options for updating. Bug fixes for security issues in 3.9.x ended on 11th December 2023....
This source does not provide full text. Read it at seclists.org.