CVE-2024-34004: Moodle Authenticated LFI risk in some misconfigured shared hosting environments
6.5
CVSS Score
3.1
Basic Information
CVE ID
GHSA ID
EPSS Score
0.55918%
CWE
Published
5/31/2024
Updated
6/4/2024
KEV Status
No
Technology
PHP
Technical Details
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| moodle/moodle | composer | >= 4.3.0, < 4.3.4 | 4.3.4 |
| moodle/moodle | composer | >= 4.2.0, < 4.2.7 | 4.2.7 |
| moodle/moodle | composer | < 4.1.10 | 4.1.10 |
Vulnerability Intelligence
Miggo AI
Root Cause Analysis
The vulnerability requires manipulation of wiki backup files during restoration. Moodle's wiki restoration process (mod_wiki) would handle path definitions in this class. The advisory specifically mentions wiki module restoration as the attack vector, and improper path handling in define_structure() would align with the described LFI scenario when combined with shared hosting misconfigurations. This matches Moodle's architecture where activity modules implement their own backup/restore logic in dedicated class files.