Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5cj-xp43-qcc3

Опубликовано: 23 окт. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

Moodle's error handling leads to sensitive information disclosure

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 5.0.0-beta, < 5.0.3

5.0.3

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.5.0-beta, < 4.5.7

4.5.7

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-548

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 месяцев назад

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
nvd
около 2 месяцев назад

An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.

CVSS3: 5.3
debian
около 2 месяцев назад

An error-handling issue in the Moodle router (r.php) could cause the a ...

EPSS

Процентиль: 12%
0.0004
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-548