PT-2006-5685 · Moodle · Moodle

Published

2006-09-23

·

Updated

2020-12-01

·

CVE-2006-4942

CVSS v2.0

4.6

Medium

VectorAV:N/AC:H/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 1.6.2
Description The issue allows remote authenticated users to write files to the top level of the dataroot directory. This can be achieved via the filter/algebra/pix.php or filter/tex/pix.php API endpoints when the configuration lacks algebra or tex filters.
Recommendations For versions prior to 1.6.2, update to version 1.6.2 or later to resolve the issue. As a temporary workaround, consider disabling the filter/algebra/pix.php and filter/tex/pix.php API endpoints until a patch is available. Restrict access to the dataroot directory to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4942

Affected Products

Moodle