-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability requires manipulation of wiki backup files during restoration. Moodle's wiki restoration process (mod_wiki) would handle path definitions in this class. The advisory specifically mentions wiki module restoration as the attack vector, and improper path handling in define_structure() would align with the described LFI scenario when combined with shared hosting misconfigurations. This matches Moodle's architecture where activity modules implement their own backup/restore logic in dedicated class files.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 4.3.0, < 4.3.4 | 4.3.4 |
| moodle/moodle | composer | >= 4.2.0, < 4.2.7 | 4.2.7 |
| moodle/moodle | composer | < 4.1.10 | 4.1.10 |
Ongoing coverage of React2Shell