Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-34005
Summary
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include. This issue affects moodle/moodle versions prior to 4.1.10, 4.2.x prior to 4.2.7, 4.3.x prior to 4.3.4, and 4.4.x prior to 4.4.0-rc2.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- LOW
- HIGH
- NONE
CWE-200 - Information Exposure
An information exposure vulnerability is categorized as an information flow (IF) weakness, which can potentially allow unauthorized access to otherwise classified information in the application, such as confidential personal information (demographics, financials, health records, etc.), business secrets, and the application's internal environment.
Advisory Timeline
- Published