CVE-2023-30943
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
- Moodle
- < 4.1.3
- Fix
- Available
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 6.6% (93th percentile)
- Weakness
- CWE-73, CWE-610
- NVD status
- Modified
- Published
- 2023-05-02
CVE-2023-30943 at NVD
5 known exploits for CVE-2023-30943
Proof-of-concept code and exploit modules indexed by Sploitus