CVE-2023-30943
MEDIUM 6.5EPSS 6.6%
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N - EPSS
- 6.58% chance of exploitation in the next 30 days, 93th percentile
- Nuclei
- medium
- Published
- 2023-05-02
- Updated
- 2024-08-02
Proof-of-concept exploits (3)
- Chocapikk/CVE-2023-3094314★ · 2023-09-07
- RubyCat1337/CVE-2023-309432★ · 2024-03-21
- d0rb/CVE-2023-3094318★ · 2024-03-13