Vulnerability record · CVE-2024-43425 · published 7 November 2024
CVE-2024-43425: Moodle calculated question types allow remote code execution
Moodle · Moodle
Moodle lacks sufficient restrictions in calculated question types, creating a code injection (CWE-94) risk that can lead to remote code execution. The flaw requires the capability to add or update questions, so it is not reachable by unauthenticated users. It matters because a user with question-authoring rights could execute code on the Moodle server.
Description
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.1 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires question-authoring privileges.
What it is
Moodle lacks sufficient restrictions in calculated question types, creating a code injection (CWE-94) risk that can lead to remote code execution. The flaw requires the capability to add or update questions, so it is not reachable by unauthenticated users. It matters because a user with question-authoring rights could execute code on the Moodle server.
Impact
An attacker with question add/update capability can inject and execute code on the Moodle server, potentially compromising the application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.
Attack surface
Reached over the network through Moodle's question authoring functionality (calculated question types). Authentication is required in practice because the description states the attacker needs the capability to add or update questions; no user interaction is indicated by the vector.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.87363, 99.7th percentile), but the references only carry Permissions Required and Vendor Advisory tags, so no public exploit is confirmed by this record.
What to do
- Apply the Moodle security update that adds the missing restrictions to calculated question types.
- Restrict the capability to add or update questions to trusted, necessary roles only.
- Review and audit existing calculated questions for unexpected or injected content.
- Monitor Moodle accounts with question-authoring permissions for unusual activity.
Detection
- Audit logs for creation or modification of calculated questions, especially by unexpected accounts.
- Look for suspicious code-like or template-injection patterns in question text and formulas.
- Monitor the Moodle web server for unexpected child processes or outbound connections following question edits.
- Alert on changes to question-authoring role assignments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2304253 | Permissions Required |
| https://moodle.org/mod/forum/discuss.php?d=461193 | Vendor Advisory |
Track CVE-2024-43425 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-43425), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.