Description
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Remediation
References
Related Vulnerabilities
MySQL CVE-2022-21328 Vulnerability (CVE-2022-21328)
WordPress Plugin Social Login Lite For WooCommerce Security Bypass (1.6.0)
concrete5 Unrestricted Upload of File with Dangerous Type Vulnerability (CVE-2020-24986)
osCommerce Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2018-18573)