CVE-2014-3541
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.
View on NVDSeverity
N/A
EPSS
Probability of exploitation (next 30 days): 0.0193 (1.9%)
Percentile: 83.5%
EPSS: 2026-05-06
Affects
moodle:moodleTechnical description
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.
Published: 7/29/2014, 11:10:31 AM
Last modified: 5/6/2026, 10:30:45 PM
References
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-45616
- http://openwall.com/lists/oss-security/2014/07/21/1
- https://moodle.org/mod/forum/discuss.php?d=264262
- http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-45616
- http://openwall.com/lists/oss-security/2014/07/21/1
- https://moodle.org/mod/forum/discuss.php?d=264262