CVE-2023-30943
MEDIUM NUCLEIMoodle - Path Traversal
Title source: llmDescription
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Exploits (3)
Nuclei Templates (1)
Moodle - Cross-Site Scripting/Remote Code Execution
MEDIUMby ritikchaddha
Shodan:
title:"Moodle" || cpe:"cpe:2.3:a:moodle:moodle" || http.title:"moodle"
FOFA:
title="moodle"
References (6)
Scores
CVSS v3
6.5
EPSS
0.1636
EPSS Percentile
94.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Classification
CWE
CWE-610
CWE-73
Status
published
Affected Products (6)
moodle/moodle
< 4.1.3
fedoraproject/extra_packages_for_enterprise_linux
fedoraproject/fedora
fedoraproject/fedora
fedoraproject/fedora
moodle/moodle
< 4.2.0-rc2Packagist
Timeline
Published
May 02, 2023
Tracked Since
Feb 18, 2026