vendor:
Moodle
by:
Christian J. Eibl
9
CVSS
CRITICAL
File Disclosure
200
CWE
Product Name: Moodle
Affected Version From: Moodle series <1.6.9+, <1.7.7+, <1.8.9, <1.9.5
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2009
Moodle File Disclosure Vulnerability
An input filter for TeX formulas can be exploited to disclose files readable by the web server. This includes the moodle configuration file with all authentication data and server locations for directly connecting to backend database.
Mitigation:
Configure LaTeX to restrict file inclusion. Ensure the temporary folder for rendering is not in the scope of the web server.