Moodle Improper Control of Generation of Code (Code Injection) Vulnerability - CVE-2018-1133
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server aka eval injection.