Description
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3592 | mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value. |
Github GHSA |
GHSA-cm4r-58pj-h2ph | Moodle allows attackers to extract archives to arbitrary directories |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T05:10:15.420Z
Reserved: 2015-03-09T00:00:00.000Z
Link: CVE-2015-2267
No data.
Status : Modified
Published: 2015-06-01T19:59:10.417
Modified: 2026-06-17T00:23:50.287
Link: CVE-2015-2267
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-284
Improper Access Control
EUVD
Github GHSA