Description
Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote authenticated users to execute arbitrary code via a calculated question in a quiz.
Remediation
References
Related Vulnerabilities
Oracle Database Server CVE-2019-2518 Vulnerability (CVE-2019-2518)
WebLogic Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2022-22965)
WordPress Plugin Flickr Justified Gallery Cross-Site Scripting (3.3.6)
WordPress Plugin YITH WooCommerce Product Add-Ons Cross-Site Scripting (2.2.2)