Description
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
Remediation
References
Related Vulnerabilities
Oracle HTTP Server NULL Pointer Dereference Vulnerability (CVE-2021-34798)
WordPress Plugin Slideshow Gallery LITE Arbitrary File Upload (1.4.6)
Plone CMS Weak Password Requirements Vulnerability (CVE-2020-7940)
Magento CVE-2019-8144 Vulnerability (CVE-2019-8144)
WordPress Plugin Sooqr Search Restricted File Upload (1.1.4)