Candidate: CVE-2016-9186 PublicDate: 2016-11-04 10:59:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-9186 https://packetstormsecurity.com/files/139466/Moodle-CMS-3.1.2-Cross-Site-Scripting-File-Upload.html https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851405 Description: Unrestricted file upload vulnerability in the "legacy course files" and "file manager" modules in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. Ubuntu-Description: Notes: ebarretto> Moodle upstream does not believe it is a security vulnerability ebarretto> and the reporter did not followed up on requests from upstream ebarretto> to provide clarification Bugs: Priority: negligible Discovered-by: Assigned-to: CVSS: nvd: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H [8.8 HIGH] Patches_moodle: upstream_moodle: needs-triage precise_moodle: ignored (reached end-of-life) precise/esm_moodle: DNE (precise was needs-triage) trusty_moodle: ignored trusty/esm_moodle: DNE (trusty was ignored) vivid/stable-phone-overlay_moodle: DNE vivid/ubuntu-core_moodle: DNE xenial_moodle: ignored yakkety_moodle: ignored (reached end-of-life) zesty_moodle: ignored (reached end-of-life) artful_moodle: ignored (reached end-of-life) bionic_moodle: ignored cosmic_moodle: ignored devel_moodle: ignored