Vulnerability Bulletins

MSA-18-0012: Portfolio script allows instantiation of class chosen by user

   
Affected software PHP
 
by Marina Glancy. Substituting URL in portfolios users can instantiate any class, this can also be exploited by users who are logged in as guests to create a DDoS attackSeverity/Risk:SeriousVersions affected:3.4 to 3.4.2, 3.3 to 3.3.5, 3.2 to 3.2.8, 3.1 to 3.1.11 and earlier unsupported versionsVersions fixed:3.5, 3.4.3, 3.3.6, 3.2.9 and 3.1.12Reported by:Brendan CoxWorkaround:Disable portfolios until the fix is applied. Portfolios are disabled by default in MoodleCVE

More info:

https://moodle.org/mod/forum/discuss.php?d=371204&parent=1496358