Description
lib/filelib.php in Moodle 2.1.x before 2.1.8, 2.2.x before 2.2.5, and 2.3.x before 2.3.2 does not properly check the publication state of blog files, which allows remote attackers to obtain sensitive information by reading a blog entry that references a non-public file.
Remediation
References
Related Vulnerabilities
PHP Use of Externally-Controlled Format String Vulnerability (CVE-2009-0754)
Envoy Proxy Uncontrolled Resource Consumption Vulnerability (CVE-2020-12605)
WordPress Plugin Video Comments Webcam Recorder Cross-Site Scripting (1.55)
WordPress Plugin Photo Gallery, Images, Slider in Rbs Image Gallery Cross-Site Scripting (3.2.12)