Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-40694


Insufficient escaping of the LaTeX preamble made it possible for site administrators to read files available to the HTTP server system account.


Published

2022-09-29T03:15:14.417

Last Modified

2024-11-21T06:24:34.930

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 4.9 (MEDIUM)

Weaknesses
  • Type: Primary
    CWE-116

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application moodle moodle < 3.9.10 Yes
Application moodle moodle < 3.10.7 Yes
Application moodle moodle < 3.11.3 Yes

References