CVE-2020-1756: Moodle
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.
Affected products
- Moodle Moodle: from 3.5.0, before 3.5.11 (fixed in 3.5.11); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.5 (fixed in 3.7.5); from 3.8.0, before 3.8.2 (fixed in 3.8.2)
Published 2022-08-16. Last modified 2026-06-17.