Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pgm5-cr62-prxq

Опубликовано: 26 июл. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Moodle Arbitrary file read when importing lesson questions

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9, < 3.9.15

3.9.15

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11, < 3.11.8

3.11.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 4.0, < 4.0.2

4.0.2

EPSS

Процентиль: 92%
0.08941
Низкий

7.5 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
nvd
почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

CVSS3: 7.5
debian
почти 3 года назад

The vulnerability was found in Moodle, occurs due to input validation ...

CVSS3: 7.5
fstec
почти 3 года назад

Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной проверкой входных данных, позволяющая нарушителю раскрыть защищаемую информацию

CVSS3: 9.8
redos
больше 2 лет назад

Множественные уязвимости Moodle

EPSS

Процентиль: 92%
0.08941
Низкий

7.5 High

CVSS3

Дефекты

CWE-20