Lucene search

K
osvGoogleOSV:GHSA-XMWV-MQH8-4XGW
HistoryMay 13, 2022 - 1:12 a.m.

Moodle allows remote attackers to read arbitrary files

2022-05-1301:12:40
Google
osv.dev
8
moodle
remote attack
file read
xml
xxe
security vulnerability

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.3%

mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

AI Score

6.8

Confidence

Low

EPSS

0.003

Percentile

70.3%