Moodle Arbitrary file read when importing lesson questions
High severity
GitHub Reviewed
Published
Jul 26, 2022
to the GitHub Advisory Database
•
Updated Apr 23, 2024
Package
Affected versions
>= 3.9, < 3.9.15
>= 3.11, < 3.11.8
>= 4.0, < 4.0.2
Patched versions
3.9.15
3.11.8
4.0.2
Description
Published by the National Vulnerability Database
Jul 25, 2022
Published to the GitHub Advisory Database
Jul 26, 2022
Reviewed
Apr 23, 2024
Last updated
Apr 23, 2024
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
References