CVE-2015-2267
Moodle < 2.5.9, 2.6.x < 2.6.9, 2.7.x < 2.7.6, 2.8.x < 2.8.4 - Arbitrary File Write via mdeploy.php
Title source: llmDescription
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.
References (3)
Core 3
Core References
Patch x_refsource_confirm
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-49087
Vendor Advisory x_refsource_confirm
https://moodle.org/mod/forum/discuss.php?d=307381
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2015/03/16/1
Scores
EPSS
0.0019
EPSS Percentile
40.5%
Details
CWE
CWE-284
Status
published
Products (30)
moodle/moodle
2.5.0
moodle/moodle
2.5.1
moodle/moodle
2.5.2
moodle/moodle
2.5.3
moodle/moodle
2.5.4
moodle/moodle
2.5.5
moodle/moodle
2.5.6
moodle/moodle
2.5.7
moodle/moodle
2.5.8
moodle/moodle
2.6.0
... and 20 more
Published
Jun 01, 2015
Tracked Since
Feb 18, 2026