« Volver al listado

CVE-2025-26525

Estado: AnalizadaAlta (8.6)—

Insufficient sanitizing in the TeX notation filter resulted in an arbitrary file read risk on sites where pdfTeX is available (such as those with TeX Live installed).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

Vector AV:N/AC:L/PR:N/UI:N indica red sin autenticación (T1190). Sanitización insuficiente en filtro TeX permite lectura arbitraria de archivos via pdfTeX, confirmado por C:H en CVSS (T1005). Riesgo de acceso a archivos sensibles en servidor.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-26525",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-26525",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-02-24T19:59:34.025897Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "patrick@puiterwijk.org",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 8.6,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 4,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "patrick@puiterwijk.org",
      "affectedData": [
        {
          "vendor": "Moodle Project",
          "product": "moodle",
          "versions": [
            {
              "status": "affected",
              "version": "4.5.0",
              "lessThan": "4.5.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.4.0",
              "lessThan": "4.4.6",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.3.0",
              "lessThan": "4.3.10",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "4.1.0",
              "lessThan": "4.1.16",
              "versionType": "semver"
            },
            {
              "status": "unknown",
              "version": "4.2.0",
              "lessThan": "4.2.*",
              "versionType": "semver"
            },
            {
              "status": "unknown",
              "version": "0",
              "lessThan": "4.0.*",
              "versionType": "semver"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-02-24T20:15:33.103",
  "references": [
    {
      "url": "https://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-84136",
      "tags": [
        "Patch"
      ],
      "source": "patrick@puiterwijk.org"
    },
    {
      "url": "https://moodle.org/mod/forum/discuss.php?d=466141",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "patrick@puiterwijk.org"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "patrick@puiterwijk.org",
      "description": [
        {
          "lang": "en",
          "value": "CWE-552"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insufficient sanitizing in the TeX notation filter resulted in an \narbitrary file read risk on sites where pdfTeX is available (such as \nthose with TeX Live installed)."
    },
    {
      "lang": "es",
      "value": " Una depuración insuficiente en el filtro de notación TeX resultó en un riesgo de lectura arbitraria de archivos en sitios donde pdfTeX esté disponible (como aquellos con TeX Live instalado)."
    }
  ],
  "lastModified": "2026-06-17T09:01:58.010",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "ABE6D6ED-55D3-46B4-84DC-7C3684E3260E",
              "versionEndExcluding": "4.1.16",
              "versionStartIncluding": "4.1.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3DF83192-5999-4E1B-B109-A1B0F68437B2",
              "versionEndExcluding": "4.3.10",
              "versionStartIncluding": "4.3.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B91CC5BB-FFB9-4D09-9001-105A8B68208E",
              "versionEndExcluding": "4.4.6",
              "versionStartIncluding": "4.4.0"
            },
            {
              "criteria": "cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "830F7FD6-3257-44A2-9599-2C5C2FF2BA20",
              "versionEndExcluding": "4.5.2",
              "versionStartIncluding": "4.5.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "patrick@puiterwijk.org"
}