CVE-2020-10738: Moodle
High severity, CVSS 8.8. EPSS: 3.1% chance of exploitation in the next 30 days.
A flaw was found in Moodle versions 3.8 before 3.8.3, 3.7 before 3.7.6, 3.6 before 3.6.10, 3.5 before 3.5.12 and earlier unsupported versions. It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
Affected products
- Moodle Moodle: from 3.5, before 3.5.12 (fixed in 3.5.12); from 3.6, before 3.6.10 (fixed in 3.6.10); from 3.7, before 3.7.6 (fixed in 3.7.6); from 3.8, before 3.8.3 (fixed in 3.8.3)
Published 2020-05-21. Last modified 2026-06-17.