Description
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user with both access to restore workshop modules and direct access to the web server outside of the Moodle webroot could execute a local file include.
Remediation
References
Related Vulnerabilities
Joomla! Core Cross-Site Scripting (1.7.0 - 3.9.5)
WordPress Plugin Timeline Event History PHP Object Injection (3.1)
Moodle Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2009-0499)
WordPress Plugin WP Dialog Cross-Site Scripting (1.2.5.5)
Django Improper Input Validation Vulnerability (CVE-2011-4139)