CVE-2025-34031
Moodle LMS Jmol Plugin Path Traversal
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
| CWE | CWE-22 |
| Vendor | moodle |
| Product | jmol plugin |
| Published | Jun 24, 2025 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for moodle jmol plugin
Be the first to know when new unknown vulnerabilities affecting moodle jmol plugin are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Moodle / Jmol Plugin
0 ≤ 6.1
References
Credits
Dionach by Nomios