A critical vulnerability in Moodle, an open source PHP-based learning management system, could expose the server its running on to compromise. Tens of thousands of universities worldwide use the service to provide students with course outlines, grades, and other personal data. The issue at its root a vulnerability could be used by an attacker to execute PHP code on a university s server according to Netanel Rubin, the researcher who found the bug. An update from early last week, 3.3.2, also includes the fix.
Source: https://threatpost.com/critical-moodle-vulnerability-could-lead-to-server-compromise/124446/