Description
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
Remediation
References
Related Vulnerabilities
Drupal Core 8.5.x Cross-Site Scripting (8.5.0 - 8.5.13)
Piwigo Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2011-3790)
Plone CMS Permissions, Privileges, and Access Controls Vulnerability (CVE-2011-4030)
Apache HTTP Server DEPRECATED: Code Vulnerability (CVE-2015-3183)