PT-2022-5148 · Moodle+2 · Moodle+2
Loknop
·
Published
2020-11-08
·
Updated
2024-03-06
·
CVE-2022-35650
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle (affected versions not specified)
Description
The issue occurs due to an input validation error when importing lesson questions, resulting in insufficient path checks. This leads to an arbitrary file read risk, allowing a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers, and admins by default. The vulnerability can be exploited by a remote attacker to disclose protected information by sending a specially crafted HTTP request.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Moodle
Red Os