Beveiligingsadvies

CVE-2012-6099

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2013-01-27 22:00:00
Laatst bijgewerkt 2024-09-17 02:52:28
Toegewezen door redhat
CVSS-score geen score
Status PUBLISHED

Beschrijving

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.