Security Advisory
CVE-2015-2267
4
Vulnerability Description
mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.
Published Date
June 1, 2015
Official Source
NIST NVD Advisory