Input validation error in Moodle - CVE-2012-6099
Published: January 28, 2013 / Updated: August 11, 2020
Moodle
Detailed vulnerability description
The vulnerability allows a remote #AU# to gain access to sensitive information.
The moodle1 backup converter in backup/converter/moodle1/lib.php in Moodle 2.1.x before 2.1.10, 2.2.x before 2.2.7, 2.3.x before 2.3.4, and 2.4.x before 2.4.1 does not properly validate pathnames, which allows remote authenticated users to read arbitrary files by leveraging the backup-restoration feature.