Loading HuntDB...

GHSA-x32v-7qw8-cpq8

GitHub Security Advisory

Moodle Unauthenticated Access

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

Affected Packages

Packagist moodle/moodle
Affected versions: 3.1.0 (fixed in 3.1.3)
Packagist moodle/moodle
Affected versions: 3.0.0 (fixed in 3.0.7)
Packagist moodle/moodle
Affected versions: 2.9.0 (fixed in 2.9.9)
Packagist moodle/moodle
Affected versions: 2.8.0 (last affected: 2.8.12)
Packagist moodle/moodle
Affected versions: 2.7.0 (fixed in 2.7.17)

Related CVEs

Key Information

GHSA ID
GHSA-x32v-7qw8-cpq8
Published
May 13, 2022 1:12 AM
Last Modified
November 2, 2023 1:25 PM
CVSS Score
5.0 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 2, 2025 6:46 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.