CVE-2023-30943
02.05.2023, 20:15
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.Enginsight
Vendor | Product | Version |
---|---|---|
moodle | moodle | 4.1.0 ≤ 𝑥 < 4.1.3 |
fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Common Weakness Enumeration
- CWE-73 - External Control of File Name or PathThe software allows user input to control or influence paths or file names that are used in filesystem operations.
- CWE-610 - Externally Controlled Reference to a Resource in Another SphereThe product uses an externally controlled name or reference that resolves to a resource that is outside of the intended control sphere.
References