A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server.
Metrics
Affected Vendors & Products
References
History
Sat, 21 Feb 2026 06:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in a Moodle TeX filter administrative setting where insufficient sanitization of configuration input could allow command injection. On sites where the TeX filter is enabled and ImageMagick is installed, a maliciously crafted setting value entered by an administrator could result in unintended system command execution. While exploitation requires administrative privileges, successful compromise could affect the entire Moodle server. | |
| Title | Moodle: moodle: improper input sanitization in tex filter administration setting | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2026-02-21T05:40:08.388Z
Reserved: 2026-02-10T13:30:03.985Z
Link: CVE-2026-26046
No data.
Status : Received
Published: 2026-02-21T06:17:00.203
Modified: 2026-02-21T06:17:00.203
Link: CVE-2026-26046
No data.
OpenCVE Enrichment
No data.