Description
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
INFO
Published Date :
2025-06-24T00:58:57.345Z
Last Modified :
2026-04-07T14:09:07.116Z
Source :
VulnCheck
AFFECTED PRODUCTS
The following products are affected by CVE-2025-34031 vulnerability.
| Vendors | Products |
|---|---|
| Geoffrowland |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-34031.