CVE-2024-43425 is a remote code execution vulnerability in Moodle affecting calculated question types. The issue stems from insufficient restrictions in the handling or processing of calculated question content, such that additional controls are required to prevent code execution. Exploitation requires an attacker to possess the capability to add or update questions in Moodle. Under those conditions, a malicious actor could craft or modify a calculated question in a way that triggers execution of attacker-controlled code on the Moodle server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a working exploit for CVE-2024-43425, an authenticated remote code execution vulnerability in Moodle (versions 4.4.0, 4.4.1, 4.3.0-4.3.5, 4.2.0-4.2.8, 4.1.0-4.1.11). The exploit is implemented in Python (app.py) and requires the 'requests' library (specified in requirements.txt). The README.md provides usage instructions and context. The exploit works by authenticating to the target Moodle instance, extracting necessary tokens and course information, and then abusing the question bank editing functionality to inject and execute arbitrary system commands on the server. The attacker must have valid credentials on the target system. The main endpoints targeted are various Moodle web application paths, and the exploit is fully operational, providing command execution on the server. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository contains a working exploit for CVE-2024-43425, a remote code execution vulnerability in Moodle. The exploit is implemented in Python (exploit.py) and is accompanied by a README.md with detailed usage instructions. The exploit targets authenticated teacher-level users with access to the quiz editing interface. It automates the process of logging in, extracting necessary session/context information, uploading a malicious calculated question containing a PHP system() payload, and then triggering arbitrary command execution via a crafted HTTP GET request. The payload leverages improper sanitization in the calculated question feature, allowing command injection. The exploit requires the attacker to provide the Moodle base URL, valid credentials, courseid, cmid, and the command to execute. The main attack vector is network-based, exploiting web endpoints exposed by Moodle. The repository is well-structured, with a single Python exploit script and a comprehensive README. No fake or detection-only code is present; the exploit is operational and provides real RCE if the target is vulnerable.
This repository contains a single Metasploit module (modules/exploits/linux/http/moodle_rce.rb) that exploits CVE-2024-43425, a command injection vulnerability in Moodle. The exploit targets Moodle versions 4.4 to 4.4.1, 4.3 to 4.3.5, 4.2 to 4.2.8, 4.1 to 4.1.11, and earlier unsupported versions running on Linux. The module requires valid credentials for a user with permission to add quiz questions, as well as knowledge of the COURSEID and CMID values, which can be obtained from the Moodle web interface URLs. The exploit works by authenticating to the Moodle web interface, navigating to the quiz question editing functionality, and injecting arbitrary commands via crafted HTTP requests. The payload is customizable and allows for arbitrary command execution, such as spawning a reverse shell. The module is operational and suitable for real-world exploitation, provided the attacker has the necessary credentials and information. The main attack vector is network-based, leveraging HTTP requests to the Moodle web application. The code is written in Ruby and is structured as a standard Metasploit exploit module.
This repository contains a single Python exploit script (exploit.py) targeting Moodle's CVE-2024-43425 remote code execution vulnerability. The exploit automates the process of authenticating to a Moodle instance, extracting necessary tokens (login token, sesskey), enumerating courses, and creating a malicious question that injects PHP code into the answer field. The injected code allows arbitrary command execution via the 'a' GET parameter. The exploit is operational and requires valid Moodle credentials. The README provides usage instructions and notes about potential issues with category IDs. The only code file is exploit.py, which is the main entry point and implements the full attack chain. The attack vector is network-based, targeting web endpoints on the Moodle server. No hardcoded IPs or domains are present; the target is specified by the user at runtime.
This repository provides proof-of-concept scripts for testing and exploiting CVE-2024-43425, a remote code execution vulnerability in Moodle's calculated question type. The structure includes two main directories: 'validation' and 'xor-generator'. The 'validation' directory contains two PHP scripts: - 'validation.php' implements the vulnerable input validation logic from Moodle 4.4.1, allowing users to test crafted input strings that can bypass validation and reach a PHP eval() call. This simulates the vulnerable environment and demonstrates how malicious input (e.g., '(1)->{phpinfo()}') can result in code execution. - 'validation-fixed.php' contains the patched logic from Moodle 4.4.2, which properly blocks such input and returns an error message instead of executing code. The 'xor-generator' directory contains 'xor-generator.py', a Python script that generates obfuscated PHP expressions to call arbitrary PHP functions using variable function names and XOR operations. This aids in crafting payloads that evade simple input filters in the vulnerable Moodle code. The repository is intended for security researchers to test the vulnerability and understand the difference between the vulnerable and fixed validation logic. It does not target a specific endpoint or IP, but rather provides tools to craft and test payloads against a Moodle instance. The main attack vector is network-based, requiring the attacker to submit malicious input to a Moodle server running a vulnerable version.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
4 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.