Executive brief
Moodle, a widely used learning management system, contains a security flaw in its question engine component. This vulnerability allows unauthorized individuals to access files that should be restricted, potentially leading to the exposure of sensitive educational materials or student data. Organizations using affected versions should apply the available security patches to prevent unauthorized information disclosure.
Technical details
An improper access control vulnerability (CWE-284) exists in the Moodle question engine. The flaw allows a remote attacker to bypass intended file access restrictions and view files that should be protected. The vulnerability is reachable over the network without requiring specific privileges or user interaction. This issue affects Moodle versions 2.7.x, 2.8.x, 2.9.x, 3.0.x, and 3.1.x. Patches have been released by the vendor to address this behavior in versions 3.0.7 and 3.1.3.
Affected products
- Moodle Moodle 2.x, 3.0.x before 3.0.7, 3.1.x before 3.1.3
Timeline
- 2016-11-21: advisory: Vendor advisory published by Moodle
- 2017-01-20: disclosed: NVD publication date