CVE-2015-2267

Moodle < 2.5.9, 2.6.x < 2.6.9, 2.7.x < 2.7.6, 2.8.x < 2.8.4 - Arbitrary File Write via mdeploy.php

Title source: llm
STIX 2.1

Description

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.

References (3)

Core 3
Core References
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=307381
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2015/03/16/1

Scores

EPSS 0.0019
EPSS Percentile 40.5%

Details

CWE
CWE-284
Status published
Products (30)
moodle/moodle 2.5.0
moodle/moodle 2.5.1
moodle/moodle 2.5.2
moodle/moodle 2.5.3
moodle/moodle 2.5.4
moodle/moodle 2.5.5
moodle/moodle 2.5.6
moodle/moodle 2.5.7
moodle/moodle 2.5.8
moodle/moodle 2.6.0
... and 20 more
Published Jun 01, 2015
Tracked Since Feb 18, 2026