### [CVE-2018-1133](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1133) ![](https://img.shields.io/static/v1?label=Product&message=Moodle%203.x%20unknown&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=eval%20injection&color=brighgreen) ### Description An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. ### POC #### Reference - https://www.exploit-db.com/exploits/46551/ #### Github - https://github.com/0xT11/CVE-POC - https://github.com/ARPSyndicate/cvemon - https://github.com/Feidao-fei/MOODLE-3.X-Remote-Code-Execution - https://github.com/That-Guy-Steve/CVE-2018-1133-Exploit - https://github.com/cocomelonc/vulnexipy - https://github.com/darrynten/MoodleExploit - https://github.com/developer3000S/PoC-in-GitHub - https://github.com/hectorgie/PoC-in-GitHub - https://github.com/jebidiah-anthony/htb_teacher - https://github.com/ra1nb0rn/search_vulns