PT-2022-5148 · Moodle+2 · Moodle+2

Loknop

·

Published

2020-11-08

·

Updated

2024-03-06

·

CVE-2022-35650

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description The issue occurs due to an input validation error when importing lesson questions, resulting in insufficient path checks. This leads to an arbitrary file read risk, allowing a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers, and admins by default. The vulnerability can be exploited by a remote attacker to disclose protected information by sending a specially crafted HTTP request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Path traversal

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3235
ALT-PU-2022-2502
ALT-PU-2022-2553
BDU:2022-06405
BIT-MOODLE-2022-35650
CVE-2022-35650
GHSA-PGM5-CR62-PRXQ

Affected Products

Alt Linux
Moodle
Red Os