CVE-2024-34005: moodle: authenticated LFI risk in some misconfigured shared hosting environments via modified mod_data backup
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore database activity modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-34005?
CVE-2024-34005 has a high severity due to its potential for local file inclusion in misconfigured shared hosting environments.
How do I fix CVE-2024-34005?
To resolve CVE-2024-34005, upgrade Moodle to version 4.1.10 or 4.2.7 or later than 4.3.4.
Who is affected by CVE-2024-34005?
Users of Moodle in shared hosting environments with misconfigurations allowing access beyond their content are affected by CVE-2024-34005.
What vulnerabilities does CVE-2024-34005 exploit?
CVE-2024-34005 exploits misconfigurations that permit unauthorized access to user content through local file inclusion.
When was CVE-2024-34005 published?
CVE-2024-34005 was published in 2024, highlighting a critical vulnerability in the Moodle platform.