#VU41451 Code Injection in Moodle - CVE-2014-3541
Published: July 29, 2014 / Updated: August 10, 2020
Moodle
moodle.org
Description
The vulnerability allows a remote non-authenticated attacker to read and manipulate data.
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.