Acceptance of Extraneous Untrusted Data With Trusted Data in Moodle - CVE-2023-5548

 

Acceptance of Extraneous Untrusted Data With Trusted Data in Moodle - CVE-2023-5548

Published: October 18, 2023


Vulnerability identifier: #VU82193
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-5548
CWE-ID: CWE-349
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise the target system.

The vulnerability exists due to acceptance of extraneous untrusted data with trusted data within file serving endpoints revision control.


Affected software

Moodle

How to mitigate CVE-2023-5548

Install updates from vendor's website.

Moodle - addressed in versions 3.9.24, 3.11.17, 4.0.11, 4.1.6, 4.2.3

External References

Related Security Bulletins