Description
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-22gj-8qj2-fj46 | Moodle External Control of File Name or Path vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-08-02T14:37:15.692Z
Reserved: 2023-04-21T00:00:00.000Z
Link: CVE-2023-30943
No data.
Status : Modified
Published: 2023-05-02T20:15:10.943
Modified: 2024-11-21T08:01:07.563
Link: CVE-2023-30943
No data.
OpenCVE Enrichment
No data.
Github GHSA