GHSA-5cvx-cwpx-9rjh
Dashboard / Vulnerabilities / GHSA-5cvx-cwpx-9rjh
GHSA-5cvx-cwpx-9rjh
Summary: Moodle Code Injection vulnerability
Details: In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-5550, https://github.com/moodle/moodle/commit/77766f9c8af8fc8d861d7ac09ce4e1f6e72faca7, https://bugzilla.redhat.com/show_bug.cgi?id=2243452, https://github.com/moodle/moodle, https://moodle.org/mod/forum/discuss.php?d=451591, http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-72249
Affected packages
Package
Name: moodle/moodle
Purl: pkg:composer/moodle/moodle
Affected ranges
Type: ECOSYSTEM
Events:
