Headline
GHSA-22gj-8qj2-fj46: Moodle External Control of File Name or Path vulnerability
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Moodle External Control of File Name or Path vulnerability
Moderate severity GitHub Reviewed Published May 2, 2023 to the GitHub Advisory Database • Updated May 2, 2023
Related news
CVE-2023-30943: Official Moodle git projects - moodle.git/search
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.