High severity7.5NVD Advisory· Published Jun 24, 2025· Updated Jun 17, 2026
CVE-2025-34031
CVE-2025-34031
Description
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
40+ 1 more
- (no CPE)range: 0
- (no CPE)range: <=6.1
- Range: <=6.1
Patches
Vulnerability mechanics
References
3- www.dionach.com/moodle-jmol-plugin-multiple-vulnerabilities/nvdExploitThird Party Advisory
- www.exploit-db.com/exploits/46881nvdExploitThird Party Advisory
- vulncheck.com/advisories/moodle-lms-jmol-plugin-path-traversalnvdThird Party Advisory
News mentions
0No linked articles in our index yet.