High severity8.8NVD Advisory· Published Nov 4, 2016· Updated Jun 17, 2026
CVE-2016-9186
CVE-2016-9186
Description
Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors.
Affected products
3- Range: <=3.1.2
Patches
Vulnerability mechanics
References
2- packetstormsecurity.com/files/139466/Moodle-CMS-3.1.2-Cross-Site-Scripting-File-Upload.htmlnvdExploitThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/94190nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.