Acceptance of Extraneous Untrusted Data With Trusted Data in Moodle - CVE-2023-5548
Published: October 18, 2023
Vulnerability identifier: #VU82193
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5548
CWE-ID: CWE-349
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to acceptance of extraneous untrusted data with trusted data within file serving endpoints revision control.
Affected software
Moodle
How to mitigate CVE-2023-5548
Install updates from vendor's website.
Moodle - addressed in versions 3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3