Improper Encoding or Escaping of Output
CVE-2021-40694
Summary
Insufficient escaping of the "LaTeX" preamble made it possible for site administrators to read files available to the HTTP server system account. This issue affects the moodle versions prior to 3.9.10, 3.10.x prior to 3.10.7, and 3.11.x prior to 3.11.3.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- HIGH
- HIGH
- NONE
CWE-116 - Improper Encoding or Escaping of Output
The software prepares a structured message for communication with another component, but encoding or escaping of the data is either missing or done incorrectly. As a result, the intended structure of the message is not preserved.
Advisory Timeline
- Published