Description
An error-handling issue in the Moodle router (r.php) could cause the application to display internal directory listings when specific HTTP headers were not properly configured.
Remediation
References
Related Vulnerabilities
Drupal Core 4.6.x Arbitrary Code Execution (4.6.0 - 4.6.6)
SharePoint CVE-2022-35823 Vulnerability (CVE-2022-35823)
Grafana Allocation of Resources Without Limits or Throttling Vulnerability (CVE-2026-28376)
PHP Other Vulnerability (CVE-2015-8835)
IBM RTC Incorrect Authorization Vulnerability (CVE-2017-1700)