CVE-2022-35650
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
- Moodle
- < 3.9.15, 3.11.8, 4.0.2
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 49.3% (99th percentile)
- Weakness
- CWE-22, CWE-20
- NVD status
- Modified
- Published
- 2022-07-25
CVE-2022-35650 at NVD
1 known exploit for CVE-2022-35650
Proof-of-concept code and exploit modules indexed by Sploitus