VDB

CVE-2020-1756

CVE-2020-1756 PUBLISHED CVSS 7.199999809265137 HIGH

In Moodle before 3.8.2, 3.7.5, 3.6.9 and 3.5.11, insufficient input escaping was applied to the PHP unit webrunner admin tool.

EPSS 0.99% · 60.2th percentile

Risk Scores

CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.99%
60.2th percentile

Affected Products

VendorProductVersions
Bitnamimoodle3.6.0, 3.7.0, 3.8.0
Bitnamimoodle3.5.0, 3.6.0, 3.7.0

Timeline

  • Mar 17, 2020 CVE Published
  • Aug 17, 2022 EPSS Score
  • Oct 2, 2022 EPSS Score
  • Nov 17, 2022 EPSS Score
  • Jan 2, 2023 EPSS Score
  • Feb 18, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 5, 2023 EPSS Score
  • May 21, 2023 EPSS Score
  • Jul 6, 2023 EPSS Score
  • Aug 21, 2023 EPSS Score
  • Oct 6, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›