Back to search
CVE-2024-34005
Published: May 31, 2024
Modified: Aug 2, 2024
PUBLISHED
Description
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
| Vendor | Product | Versions |
|---|---|---|
Unknown | Moodle | affected 4.0 - <= 4.3.3affected 4.2 - <= 4.2.6affected 4.1 - <= 4.1.9 |
Weaknesses (CWE)
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now