The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
References
Configurations
History
No history.
Information
Published : 2022-07-25 16:15
Updated : 2023-11-07 03:49
NVD link : CVE-2022-35650
Mitre link : CVE-2022-35650
CVE.ORG link : CVE-2022-35650
JSON object : View
Products Affected
moodle
- moodle
fedoraproject
- fedora