CVE-2018-1137
UnknownEPSS 1.67%
Last modified
CVE-2018-1137 is a vulnerability of currently unknown severity. An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. EPSS estimates a 1.67% chance of exploitation in the next 30 days.
Description
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | >= 3.1.0, <= 3.1.11 |
| Moodle | Moodle | >= 3.2.0, <= 3.2.8 |
| Moodle | Moodle | >= 3.3.0, <= 3.3.5 |
| Moodle | Moodle | >= 3.4.0, <= 3.4.2 |
References
- http://www.securityfocus.com/bid/104307Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=371204Vendor Advisory
- http://www.securityfocus.com/bid/104307Third Party Advisory, VDB Entry
- https://moodle.org/mod/forum/discuss.php?d=371204Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1137?
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
How severe is CVE-2018-1137?
Severity scoring for CVE-2018-1137 is pending analysis. The EPSS model estimates a 1.67% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1137?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-11363jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap…
- CVE-2018-11364sav_parse_machine_integer_info_record in spss/readstat_sav_r…
- CVE-2018-11365sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.…
- CVE-2018-11366init.php in the Loginizer plugin 1.3.8 through 1.3.9 for Wor…
- CVE-2018-11367An issue was discovered in CppCMS before 1.2.1. There is a d…
- CVE-2018-11369An issue was discovered in PbootCMS v1.0.9. There is a SQL I…
- CVE-2018-11371SkyCaiji 1.2 allows CSRF to add an Administrator user.
- CVE-2018-11372iScripts eSwap v2.4 has SQL injection via the wishlistdetail…
- CVE-2018-11373iScripts eSwap v2.4 has SQL injection via the "salelistdetai…
- CVE-2018-11375The _inst__lds() function in radare2 2.5.0 allows remote att…
- CVE-2018-11376The r_read_le32() function in radare2 2.5.0 allows remote at…
- CVE-2018-11377The avr_op_analyze() function in radare2 2.5.0 allows remote…
Are you affected by CVE-2018-1137?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
