In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: fedora
Published: 2023-11-09T19:38:08.611Z
Updated: 2024-08-02T07:59:44.743Z
Reserved: 2023-10-12T00:50:39.990Z
Link: CVE-2023-5550
Vulnrichment
Updated: 2024-08-02T07:59:44.743Z
NVD
Status : Modified
Published: 2023-11-09T20:15:10.867
Modified: 2024-11-21T08:41:59.613
Link: CVE-2023-5550
Redhat
No data.