CVE-2023-28330
Moodle: authenticated arbitrary file read through malformed backup file
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.5EPSS 1.2%KEV nãoPoC —Patch referenciado
Lifecycle
Mar 23, 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
moodleWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →