Untriaged
Moodle: rce due to lfi risk in some misconfigured shared hosting environments
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Affected products
moodle
- <3.11.17
- <4.0.11
- <4.1.6
- <4.2.3
- <3.9.24
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>