Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-56r9-72vx-q989

Опубликовано: 23 мар. 2023
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

Moodle arbitrary file read vulnerability

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.1.0, < 4.1.2

4.1.2

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.0.0, < 4.0.7

4.0.7

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11.0, < 3.11.13

3.11.13

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 3.9.20

3.9.20

EPSS

Процентиль: 60%
0.00401
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 6.5
ubuntu
больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
nvd
больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 6.5
debian
больше 2 лет назад

Insufficient sanitizing in backup resulted in an arbitrary file read r ...

EPSS

Процентиль: 60%
0.00401
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-20