Description
Directory traversal vulnerability in the min_get_slash_argument function in lib/configonlylib.php in Moodle through 2.5.9, 2.6.x before 2.6.8, 2.7.x before 2.7.5, and 2.8.x before 2.8.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter, as demonstrated by reading PHP scripts.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21318 Vulnerability (CVE-2022-21318)
WordPress Plugin Cardinity Payment Gateway for WooCommerce Cross-Site Scripting (3.0.6)
WordPress Plugin Gwolle Guestbook Remote File Inclusion (1.5.3)
WordPress Plugin Traffic Manager Multiple Vulnerabilities (1.4.5)
WordPress Plugin Gutenberg Block Editor Toolkit-EditorsKit Remote Code Execution (1.31.5)