CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. Its EPSS score suggests a 49.1% probability of exploitation in the next 30 days. It may be remotely exploitable.
CVE
CVE-2022-35650
Severity
HIGH
CVSS
7.5
EPSS
49.10%
Original NVD Description
The vulnerability was found in Moodle, occurs due to input validation error when importing lesson questions. This insufficient path checks results in arbitrary file read risk. This vulnerability allows a remote attacker to perform directory traversal attacks. The capability to access this feature is only available to teachers, managers and admins by default.
Related CVEs
Other vulnerabilities affecting the same vendor(s)