CVE-2024-43425
Moodle: remote code execution via calculated question types
- Published
- Nov 7, 2024
- Updated
- Nov 7, 2024
- Assigning CNA
- fedora
- Evidence observed
- Jul 2, 2025
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 99.8%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
Summary
A flaw was found in Moodle. Additional restrictions are required to avoid a remote code execution risk in calculated question types. Note: This requires the capability to add/update questions.
Sources
6- CVE-2024-43425-PocExploit
Proof-of-concept exploit for Moodle CVE-2024-43425, enabling authenticated RCE via crafted calculated questions. Automates login, token extraction, payload upload, and trigger for security testing.
- Moodle-authenticated-RCEExploit
🚀 Exploit for Moodle 4.4.0 Authenticated RCE (CVE-2024-43425) — run commands remotely ⚡
- cve-2024-43425Exploit
Detailed technical analysis and proof-of-concept exploit for CVE-2024-43425, a Moodle remote code execution vulnerability via calculated question formulas, including root cause and reproduction steps.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.