← Back

CVE-2022-35650

nvd nist
Published: Jul 25, 2022Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.

Affected (5)

1 product
Moodle
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.11.0 to 3.11.8
From 3.9.0 to 3.9.15
From 4.0.0 to 4.0.2
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36

Timeline

No history available yet.