Description
The Repositories component in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary code via serialized data associated with an add-on.
Remediation
References
Related Vulnerabilities
WordPress Plugin BP Profile Search PHP Object Injection (4.5.3)
Django Use of Persistent Cookies Containing Sensitive Information Vulnerability (CVE-2026-35192)
WordPress Plugin VikRentCar Car Rental Management System Cross-Site Request Forgery (1.1.6)
Undertow CVE-2022-2764 Vulnerability (CVE-2022-2764)
Drupal Permissions, Privileges, and Access Controls Vulnerability (CVE-2012-4553)