#VU49972 PHP file inclusion in Moodle - CVE-2021-20187
Published: January 25, 2021
Moodle
moodle.org
Description
The vulnerability allows a remote administrator to include and execute arbitrary PHP files on the server.
The vulnerability exists due to incorrect input validation when including PHP files during Shibboleth authentication. A remote administrator can include and execute arbitrary PHP code on the system with privileges of the web server.