GHSA-pgm5-cr62-prxq
GitHub Security Advisory
Moodle Arbitrary file read when importing lesson questions
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
Affected Packages
Packagist
moodle/moodle
Affected versions:
3.9
(fixed in 3.9.15)
Packagist
moodle/moodle
Affected versions:
3.11
(fixed in 3.11.8)
Packagist
moodle/moodle
Affected versions:
4.0
(fixed in 4.0.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: June 15, 2025 6:24 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.