A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=2128147 | issue tracking third party advisory |
https://moodle.org/mod/forum/discuss.php?d=438393 | patch vendor advisory |