vulnerability
Moodle: Unspecified Security Vulnerability (CVE-2023-28330)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:C/I:N/A:N) | Mar 23, 2023 | Mar 29, 2023 | Jan 28, 2025 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:C/I:N/A:N)
Published
Mar 23, 2023
Added
Mar 29, 2023
Modified
Jan 28, 2025
Description
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
Solutions
moodle-upgrade-3_11_13moodle-upgrade-3_9_20moodle-upgrade-4_0_7
References
- CVE-2023-28330
- https://attackerkb.com/topics/CVE-2023-28330
- URL-https://bugzilla.redhat.com/show_bug.cgi?id=2179412
- URL-https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/
- URL-https://moodle.org/mod/forum/discuss.php?d=445062
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.