vulnerability
Moodle: Improper Input Validation (CVE-2023-28330)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:N/AC:L/Au:S/C:C/I:N/A:N) | Mar 23, 2023 | Mar 29, 2023 | May 7, 2026 |
Severity
7
CVSS
(AV:N/AC:L/Au:S/C:C/I:N/A:N)
Published
Mar 23, 2023
Added
Mar 29, 2023
Modified
May 7, 2026
Description
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
Solution
moodle-upgrade-latest
References
- CVE-2023-28330
- https://attackerkb.com/topics/CVE-2023-28330
- https://bugzilla.redhat.com/show_bug.cgi?id=2179412
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/
- https://moodle.org/mod/forum/discuss.php?d=445062
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-0878
- CWE-20
- EUVD-EUVD-2023-0878
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.