Input validation error in Moodle - CVE-2012-6099

 

Input validation error in Moodle - CVE-2012-6099

Published: January 28, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU43144
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2012-6099
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote #AU# to gain access to sensitive information.

The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.


Affected software

Moodle

How to mitigate CVE-2012-6099

Install update from vendor's website.


External References

Related Security Bulletins