7.5
CVSSv2

CVE-2013-5674

Published: 16/09/2013 Updated: 01/12/2020
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

badges/external.php in Moodle 2.5.x prior to 2.5.2 does not properly handle an object obtained by unserializing a description of an external badge, which allows remote malicious users to conduct PHP object injection attacks via unspecified vectors, as demonstrated by overwriting the value of the userid parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

moodle moodle 2.5.0

moodle moodle 2.5.1

Exploits

Moodle CMS version 250-1 suffers from a cross site scripting vulnerability ...

Github Repositories

Security Advisories and Researches

Advisories Security advisories I've published in the latest years VMTurbo Operations Remote Command Execution VMTurbo Operations Manager appliance can be exploited by an unauthenticated attacker to execute unauthenticated arbitrary remote commands 25-07-2014 | CVE-2014-5073 | Original advisory | Advisory details | Metasploit Module | Status: Fixed in 46-28657 Moodle XSS