CVE-2020-1756: Moodle

High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

Affected products

  • Moodle Moodle: from 3.5.0, before 3.5.11 (fixed in 3.5.11); from 3.6.0, before 3.6.9 (fixed in 3.6.9); from 3.7.0, before 3.7.5 (fixed in 3.7.5); from 3.8.0, before 3.8.2 (fixed in 3.8.2)

Published 2022-08-16. Last modified 2026-06-17.