← Vulnerability feed

Vulnerability record · CVE-2024-43425 · published 7 November 2024

CVE-2024-43425: Moodle calculated question types allow remote code execution

Moodle · Moodle

Moodle lacks sufficient restrictions in calculated question types, creating a code injection (CWE-94) risk that can lead to remote code execution. The flaw requires the capability to add or update questions, so it is not reachable by unauthenticated users. It matters because a user with question-authoring rights could execute code on the Moodle server.

8.1 CVSS 3.1 High EPSS 88% · top 0.2% CWE-94 · Code injection
8.1CVSS 3.1 base score
88%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityCVSS 8.1 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires question-authoring privileges.

What it is

Moodle lacks sufficient restrictions in calculated question types, creating a code injection (CWE-94) risk that can lead to remote code execution. The flaw requires the capability to add or update questions, so it is not reachable by unauthenticated users. It matters because a user with question-authoring rights could execute code on the Moodle server.

Impact

An attacker with question add/update capability can inject and execute code on the Moodle server, potentially compromising the application and its data. The CVSS vector rates confidentiality, integrity and availability impact as high.

Attack surface

Reached over the network through Moodle's question authoring functionality (calculated question types). Authentication is required in practice because the description states the attacker needs the capability to add or update questions; no user interaction is indicated by the vector.

Exploitation

Not listed in CISA KEV and no ransomware usage is documented. EPSS is very high (0.87363, 99.7th percentile), but the references only carry Permissions Required and Vendor Advisory tags, so no public exploit is confirmed by this record.

What to do

  • Apply the Moodle security update that adds the missing restrictions to calculated question types.
  • Restrict the capability to add or update questions to trusted, necessary roles only.
  • Review and audit existing calculated questions for unexpected or injected content.
  • Monitor Moodle accounts with question-authoring permissions for unusual activity.

Detection

  • Audit logs for creation or modification of calculated questions, especially by unexpected accounts.
  • Look for suspicious code-like or template-injection patterns in question text and formulas.
  • Monitor the Moodle web server for unexpected child processes or outbound connections following question edits.
  • Alert on changes to question-authoring role assignments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-43425 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2019-3809Moodle cross-site request forgery vulnerabilityA flaw was found in Moodle versions 3.1 to 3.1.15 and earlier unsupported versions. The mybackpack functionality allowed setting the URL of badges, w…EPSS 0.86%10.0CVE-2006-4935Moodle improper input validation vulnerabilityThe Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and remote attack vectors.EPSS 1.5%10.0CVE-2006-4936Moodle improper input validation vulnerabilityMoodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has unspecified impact and remote a…EPSS 1.5%10.0CVE-2005-2247Moodle vulnerabilityMultiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.EPSS 1.5%10.0CVE-2004-2233Moodle vulnerabilityUnknown "front page vulnerability with Moodle servers" for Moodle before 1.3.2 has unknown impact and attack vectors.EPSS 1.7%10.0CVE-2004-2235Moodle vulnerabilityUnknown vulnerability in Moodle before 1.2 has unknown impact and attack vectors, related to improper filtering of text.EPSS 1.4%10.0CVE-2004-2236Moodle vulnerabilityUnknown vulnerability in Moodle before 1.3.3 has unknown impact and attack vectors, related to language setting.EPSS 1.4%10.0CVE-2004-2237Moodle vulnerabilityUnknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."EPSS 1.7%

Source: NIST National Vulnerability Database (record CVE-2024-43425), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.