Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-22gj-8qj2-fj46: Moodle External Control of File Name or Path vulnerability

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

ghsa
#vulnerability#git

Moodle External Control of File Name or Path vulnerability

Moderate severity GitHub Reviewed Published May 2, 2023 to the GitHub Advisory Database • Updated May 2, 2023

Related news

CVE-2023-30943: Official Moodle git projects - moodle.git/search

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.