Vulnerability Details
Basic Information
| Title | GHSA-C8V6-VXHF-WCRR Moodle has an authenticated remote code execution risk in the Moodle LMS Dropbox repository |
|---|---|
| Type | osv |
| Published | 2025-04-25T15:31:23 |
| Last Seen | 2025-04-25T19:36:15 |
| CVSS Score | 8.8 (HIGH) |
CVSS v3 Details
| Attack Vector | NETWORK |
|---|---|
| Attack Complexity | LOW |
| Privileges Required | LOW |
| User Interaction | NONE |
| Scope | UNCHANGED |
| Confidentiality Impact | HIGH |
| Integrity Impact | HIGH |
| Availability Impact | HIGH |
CVE Information
| CVE IDs | CVE-2025-3641 |
|---|---|
| CWE | |
| Bulletin Family | software |
Description
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
Impact Assessment
| Base Score | 8.8 |
|---|---|
| Severity | HIGH |