Moodle
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*
- >= 5.0, <= 5.0.2
- >= 4.5, <= 4.5.6
A vulnerability in the Moodle router (r.php) has been identified, where improper error handling can lead to the application unintentionally disclosing internal directory listings. This issue arises when certain HTTP headers are not correctly configured, potentially exposing the file structure or sensitive application information. The vulnerability affects Moodle versions 5.0 prior to 5.0.3 and 4.5 prior to 4.5.7.
Exploitation of this vulnerability can result in the exposure of internal directory listings, which may include sensitive information such as application files, source code, or other data that could be leveraged for further exploitation.
Users can upgrade to Moodle versions 5.0.3 or 4.5.7 to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.