Moodle has an arbitrary file read risk through pdfTeX
High severity
GitHub Reviewed
Published
Feb 24, 2025
to the GitHub Advisory Database
•
Updated Feb 24, 2025
Package
Affected versions
>= 4.5.0-beta, < 4.5.2
>= 4.4.0-beta, < 4.4.6
>= 4.3.0-beta, < 4.3.10
< 4.1.16
Patched versions
4.5.2
4.4.6
4.3.10
4.1.16
Description
Published by the National Vulnerability Database
Feb 24, 2025
Published to the GitHub Advisory Database
Feb 24, 2025
Reviewed
Feb 24, 2025
Last updated
Feb 24, 2025
Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as
those with TeX Live installed).
References