Description
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
Problem types
Improper Control of Generation of Code ('Code Injection')
Product status
4.5.0 (semver) before 4.5.4
4.4.0 (semver) before 4.4.8
4.3.0 (semver) before 4.3.12
4.1.0 (semver) before 4.1.18
Timeline
| 2025-04-15: | Reported to Red Hat. |
| 2025-04-22: | Made public. |
Credits
Red Hat would like to thank Vincent Schneider for reporting this issue.
References
access.redhat.com/security/cve/CVE-2025-3641
bugzilla.redhat.com/show_bug.cgi?id=2359735 (RHBZ#2359735)
moodle.org/mod/forum/discuss.php?d=467602