CVE-2015-2267

Publication date

2015-06-01 19:00:00

Family

mitre

State

PUBLISHED

Description

mdeploy.php in Moodle through 2.5.9, 2.6.x before 2.6.9, 2.7.x before 2.7.6, and 2.8.x before 2.8.4 allows remote authenticated users to bypass intended access restrictions and extract archives to arbitrary directories via a crafted dataroot value.