Moodle allows remote attackers to read arbitrary files
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 19, 2024
Package
Affected versions
<= 2.3.11
>= 2.4.0, < 2.4.11
>= 2.5.0, < 2.5.7
>= 2.6.0, < 2.6.4
= 2.7.0
Patched versions
2.4.11
2.5.7
2.6.4
2.7.1
Description
Published by the National Vulnerability Database
Jul 29, 2014
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jan 19, 2024
Last updated
Jan 19, 2024
mod/lti/service.php in Moodle through 2.3.11, 2.4.x before 2.4.11, 2.5.x before 2.5.7, 2.6.x before 2.6.4, and 2.7.x before 2.7.1 allows remote attackers to read arbitrary files via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
References