CVE-2008-5153

EPSS 0.03%

Moodle vulnerable to symlink attack

Published: 5/17/2022Modified: 2/9/2024
Also known as:GHSA-x7r4-26m9-hmgq

Description

`spell-check-logic.cgi` in Moodle 1.9 before 1.9.4, 1.8 before 1.8.8, 1.7 before 1.7.7 and 1.6 before 1.6.9 allows local users to overwrite arbitrary files via a symlink attack on the (1) `/tmp/spell-check-debug.log`, (2) `/tmp/spell-check-before`, or (3) `/tmp/spell-check-after` temporary file.

Affected packages (2)

References (8)