mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.014
EPSS Ranking 69.9%