MSA-20-0006: Remote code execution possible via SCORM packages
It was possible to create a SCORM package in such a way that when added to a course, it could be interacted with via web services in order to achieve remote code execution.
Severity/Risk: | Serious |
Versions affected: | 3.8 to 3.8.2, 3.7 to 3.7.5, 3.6 to 3.6.9, 3.5 to 3.5.11 and earlier unsupported versions |
Versions fixed: | 3.8.3, |