Description
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
Remediation
References
Related Vulnerabilities
WordPress Plugin Chameleon CSS SQL Injection (1.2)
WordPress Plugin Comments-wpDiscuz Arbitrary File Upload (7.0.4)
ASP.NET MVC Improper Input Validation Vulnerability (CVE-2017-0247)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.28)
WordPress Plugin Display Widgets Cross-Site Scripting (2.03)