Back

HIGH

moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_data backup

Published May 31, 2024

Description

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner fedora
Published May 31, 2024
Updated Aug 2, 2024
Reserved Apr 29, 2024
CISA Vulnrichment
Updated Jun 3, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-R99Q-HMQV-XW8W