vulnerability

Moodle: Improper Input Validation (CVE-2022-35650)

Severity
8
CVSS
(AV:N/AC:L/Au:N/C:C/I:N/A:N)
Published
Jul 25, 2022
Added
Aug 3, 2022
Modified
Jan 28, 2025

Description

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

Solutions

moodle-upgrade-3_11_8moodle-upgrade-3_9_15moodle-upgrade-4_0_2
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.