CVE-2023-5550
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
- Moodle
- < 3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 1.4% (69th percentile)
- Weakness
- CWE-94
- NVD status
- Modified
- Published
- 2023-11-09
CVE-2023-5550 at NVD
No indexed exploits for CVE-2023-5550 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2023-5550 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.