CVE-2022-35650

HIGH7.5EPSS 0.44%

Moodle Arbitrary file read when importing lesson questions

發布日:2022/7/26修改日:2024/4/24
也稱為:GHSA-pgm5-cr62-prxqBIT-moodle-2022-35650

描述

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

參考連結(9)