The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
3.9.0 | 3.9.15 |
moodle / moodle
|
3.11.0 | 3.11.8 |
moodle / moodle
|
4.0.0 | 4.0.2 |
| fedoraproject / fedora | 35 | 35.x |
| fedoraproject / fedora | 36 | 36.x |