The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
{
"cwe_ids": [
"CWE-20"
],
"nvd_published_at": "2022-07-25T16:15:00Z",
"github_reviewed": true,
"severity": "HIGH",
"github_reviewed_at": "2024-04-23T23:36:44Z"
}