Rapid7 Vulnerability & Exploit Database

Moodle: Improper Input Validation (CVE-2022-35650)

Back to Search

Moodle: Improper Input Validation (CVE-2022-35650)

Severity
4
CVSS
(AV:L/AC:M/Au:N/C:P/I:P/A:P)
Published
07/25/2022
Created
08/29/2022
Added
08/03/2022
Modified
08/03/2022

Description

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

Solution(s)

  • moodle-upgrade-3_11_8
  • moodle-upgrade-3_9_15
  • moodle-upgrade-4_0_2

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;