Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8rc7-4qfv-4484

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle does not properly restrict file access

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 2.4.10

2.4.10

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.5.0, < 2.5.6

2.5.6

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.6.0, < 2.6.3

2.6.3

EPSS

Процентиль: 51%
0.00283
Низкий

Связанные уязвимости

ubuntu
около 11 лет назад

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

nvd
около 11 лет назад

The My Home implementation in the block_html_pluginfile function in blocks/html/lib.php in Moodle through 2.3.11, 2.4.x before 2.4.10, 2.5.x before 2.5.6, and 2.6.x before 2.6.3 does not properly restrict file access, which allows remote attackers to obtain sensitive information by visiting an HTML block.

debian
около 11 лет назад

The My Home implementation in the block_html_pluginfile function in bl ...

EPSS

Процентиль: 51%
0.00283
Низкий