CVE-2025-34031: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Moodle Jmol Plugin
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
AI Analysis
Technical Summary
The Moodle Jmol plugin version 6.1 and prior contains a path traversal vulnerability (CWE-22) in the jsmol.php script. The script accepts a query parameter that is passed directly to the PHP file_get_contents() function without sanitization or validation. This flaw enables remote attackers to craft malicious requests that read arbitrary files from the server filesystem. The vulnerability requires no authentication and has a CVSS 4.0 score of 8.7 (high severity), reflecting its network attack vector, low complexity, no privileges required, no user interaction, and high confidentiality impact. Exploitation evidence was documented by Shadowserver Foundation on 2025-02-02 UTC. No patch or official fix has been disclosed as of the publication date.
Potential Impact
Successful exploitation allows unauthenticated attackers to read arbitrary files on the affected server, potentially exposing sensitive configuration files including database credentials. This can lead to further compromise of the Moodle LMS environment or connected systems. The high CVSS score indicates a significant confidentiality impact with no required privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider restricting access to the vulnerable jsmol.php script or applying web application firewall (WAF) rules to block malicious path traversal attempts. Monitoring for exploitation attempts is advised given the observed exploitation evidence.
CVE-2025-34031: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Moodle Jmol Plugin
Description
A path traversal vulnerability exists in the Moodle LMS Jmol plugin version 6.1 and prior via the query parameter in jsmol.php. The script directly passes user input to the file_get_contents() function without proper validation, allowing attackers to read arbitrary files from the server's filesystem by crafting a malicious query value. This vulnerability can be exploited without authentication and may expose sensitive configuration data, including database credentials. Exploitation evidence was observed by the Shadowserver Foundation on 2025-02-02 UTC.
CVSS v4.0
Score 8.7high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Moodle Jmol plugin version 6.1 and prior contains a path traversal vulnerability (CWE-22) in the jsmol.php script. The script accepts a query parameter that is passed directly to the PHP file_get_contents() function without sanitization or validation. This flaw enables remote attackers to craft malicious requests that read arbitrary files from the server filesystem. The vulnerability requires no authentication and has a CVSS 4.0 score of 8.7 (high severity), reflecting its network attack vector, low complexity, no privileges required, no user interaction, and high confidentiality impact. Exploitation evidence was documented by Shadowserver Foundation on 2025-02-02 UTC. No patch or official fix has been disclosed as of the publication date.
Potential Impact
Successful exploitation allows unauthenticated attackers to read arbitrary files on the affected server, potentially exposing sensitive configuration files including database credentials. This can lead to further compromise of the Moodle LMS environment or connected systems. The high CVSS score indicates a significant confidentiality impact with no required privileges or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, administrators should consider restricting access to the vulnerable jsmol.php script or applying web application firewall (WAF) rules to block malicious path traversal attempts. Monitoring for exploitation attempts is advised given the observed exploitation evidence.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.546Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6859fad3dec26fc862d8c367
Added to database: 06/24/2025, 01:09:39 UTC
Last enriched: 05/14/2026, 01:52:15 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 128
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.