CVE-2024-34003: moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_workshop backup
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34003?
CVE-2024-34003 is considered a medium severity vulnerability due to the potential for local file inclusion in misconfigured shared environments.
How do I fix CVE-2024-34003?
To fix CVE-2024-34003, upgrade to Moodle version 4.1.10, 4.2.7, or 4.3.4.
What systems are affected by CVE-2024-34003?
CVE-2024-34003 affects Moodle instances that are misconfigured in a shared hosting environment allowing user access outside of the Moodle webroot.
Who is impacted by CVE-2024-34003?
CVE-2024-34003 can impact Moodle users who have restore workshop module access and web server access.
What is the risk of CVE-2024-34003?
The risk of CVE-2024-34003 includes unauthorized access to sensitive content due to local file inclusion vulnerabilities.