Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w66h-c2vj-cm7f

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью

Описание

Moodle Authentication Bypass in File Upload

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 2.3, < 2.3.1

2.3.1

EPSS

Процентиль: 50%
0.00269
Низкий

Дефекты

CWE-287

Связанные уязвимости

ubuntu
почти 13 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

nvd
почти 13 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether references are permitted in a file upload, which allows remote authenticated users to bypass intended alias (aka shortcut) restrictions via a client that omits this check.

debian
почти 13 лет назад

Moodle 2.3.x before 2.3.1 uses only a client-side check for whether re ...

EPSS

Процентиль: 50%
0.00269
Низкий

Дефекты

CWE-287