CVE-2023-5550
09.11.2023, 20:15
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Vendor | Product | Version |
---|---|---|
moodle | moodle | 𝑥 < 3.9.24 |
moodle | moodle | 3.11.0 ≤ 𝑥 < 3.11.17 |
moodle | moodle | 4.0.0 ≤ 𝑥 < 4.0.11 |
moodle | moodle | 4.1.0 ≤ 𝑥 < 4.1.6 |
moodle | moodle | 4.2.0 ≤ 𝑥 < 4.2.3 |
fedoraproject | extra_packages_for_enterprise_linux | 7.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References