mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-27 10:22:48 +02:00
18 lines
768 B
Markdown
18 lines
768 B
Markdown
### [CVE-2021-20187](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-20187)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://moodle.org/mod/forum/discuss.php?d=417171
|
|
|
|
#### Github
|
|
- https://github.com/jev770/badmoodle-scan
|
|
|