Description
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2010-0066 Vulnerability (CVE-2010-0066)
WordPress Plugin iThemes Security (formerly Better WP Security) Cross-Site Scripting (3.2.4)
Atlassian Confluence Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-29450)
WordPress Plugin WP-RecentComments 'page' Parameter Cross-Site Scripting (2.0.6)