A vulnerability has been reported in Moodle, which can be exploited by malicious people to disclose potentially sensitive information.
The vulnerability is caused due to an error in the "min_get_slash_argument()" function (lib/configonlylib.php), and can be exploited to disclose contents of arbitrary files via directory traversal sequences.
The vulnerability is reported in versions 2.8 through 2.8.2, 2.7 through 2.7.4, and 2.6 through 2.6.7.