Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <CAOnRL-WBJFx70z-_aCbnyRWvAgUkxvcJPmqQ-YAcsLzuT=L7Dw@mail.gmail.com>
Date: Mon, 28 Sep 2026 22:34:55 +0500
From: Muhammad Arslan Official <arslanqofficial@...il.com>
To: oss-security@...ts.openwall.com
Subject: Moodle LMS 3.9.2: authenticated file-upload validation bypass
 (CWE-434) leading to RCE under misconfiguration

Hello,

I am disclosing a vulnerability in Moodle LMS and requesting a CVE ID, as
the
vendor (a registered CNA) has not assigned one after coordinated disclosure,
and a MITRE CNA-LR request (CAN-2026-2032565) has been under review for ~3
months without response.

Product: Moodle LMS
Confirmed version: 3.9.2 (other versions not yet verified)
Class: CWE-434 / CWE-20 - Unrestricted file upload / improper input
validation
Privilege required: authenticated, Student-level account
Vendor status: reported via Bugcrowd 2025-08-31, triaged P3 (2025-09-06);
vendor acknowledged the behaviour but has not assigned a CVE or committed
to a
code fix.

Summary
-------
The user profile picture upload is intended to accept images only and
enforces
this through multiple server- and client-side validation layers. All of
these
can be bypassed, allowing an authenticated Student-level user to store a
non-image, server-executable file (a PHP web shell). The bypass combines a
spoofed Content-Type, a non-image executable extension, a valid image magic-
byte header prepended to the payload, and manipulation of the client-side
accepted_types control.

Impact
------
The validation bypass (a code-level defect) is independent of server config.
Where the Moodle data directory (moodledata) is located inside the web root
-
a configuration Moodle documents as forbidden but which occurs in practice -
the stored file is directly reachable and executes, resulting in remote code
execution in the web-server context. Even in hardened configurations, the
stored payload is a durable chaining primitive for any file-inclusion flaw.

Disclosure timeline
-------------------
2025-08-31  Reported to vendor via Bugcrowd
2025-09-06  Triaged and accepted P3 by Bugcrowd
2025-11 to 2026-05  Vendor technical discussion; no fix commitment, no CVE
2026-06-27  MITRE CNA-LR request filed (CAN-2026-2032565) - still under
review
2026-09     Public disclosure via this post

I am withholding the full step-by-step exploit chain and PoC here, since no
patch exists, but can provide complete technical documentation (intercepted
requests, reproduction steps, command-execution evidence) to coordinators or
the vendor on request.

Requesting a CVE ID for this issue.

Regards,
Muhammad Arslan Qureshi (unlitshadow)

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.