CVE-2024-34005

CVE-2024-34005: moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_data backup

Weakness CWE-200 · Info exposure
Published May 31, 2024
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.

Key dates

02Disclosure timeline

May 31, 2024 CVE published
August 2, 2024 Record updated