A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
https://moodle.org/mod/forum/discuss.php?d=467602
https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-12520