vendor:
Moodle
by:
Sirwan Veisi
7.5
CVSS
HIGH
Unrestricted File Upload
434
CWE
Product Name: Moodle
Affected Version From: Moodle Versions 3.8, 3.7, 3.6, 3.5, 3.4...
Affected Version To: Moodle Version 3.8
Patch Exists: NO
Related CWE: N/A
CPE: moodle
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Moodle Version 3.8
2019
Moodle 3.8 – Unrestricted File Upload
I found an Unrestricted Upload vulnerability for Moodle version 3.8 , that allows the attacker to upload or transfer files of dangerous types.
Mitigation:
Ensure that the application is configured to only allow uploads of files with appropriate extensions and validate the content of the uploaded files.