Re: Moodle LMS 3.9.2: authenticated file-upload validation bypass (CWE-434) leading to RCE under misconfiguration
Poster questions a CVE for an authenticated Moodle 3.9.2 upload bypass that needs misconfiguration for RCE.
An oss-security thread discusses an authenticated file-upload validation bypass (CWE-434) in Moodle LMS 3.9.2 that could lead to remote code execution only under misconfiguration. Michael Straßberger notes that Moodle 3.9 no longer has security support and asks whether the behavior reproduces on at least Moodle 4.1.22. He argues a CVE should not be issued if supported releases are unaffected, citing already high advisory volume. No CVE identifier or observed exploitation is stated.
- Authenticated file-upload validation bypass reported in Moodle 3.9.2
- Remote code execution claimed only if the server is misconfigured
- Moodle 3.9 no longer receives security support
- Poster asks if the issue reproduces on supported Moodle 4.1.22 before any CVE
Posted by Michael Straßberger on Sep 29 Hello, https://download.moodle.org/releases/security/ it does not even have Security Support any more. Is this Behaviour reproducible in at least Moodle 4.1.22? If not I don't think a CVE should be issued here, since it would only increase the Noise. The Influx of CVE's and advisory is high as is and I don't think it's...
This source does not provide full text. Read it at seclists.org.