MEDIUM
theme/yui_combo.php in Moodle 2.3.x before 2.3.2 does not properly construct error responses for the drag-and-drop script, which allows remote attackers to obtain the installation path by sending a request for a nonexistent resource and then reading the response
Published Sep 19, 2012
5.0
MEDIUMCVSS 2.0
EPSS 1.40%
Description
Affected products
Remediation
Metrics
References (3)
Change history (0)
No recorded changes yet.