Vulnerability Description
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | < 3.9.20 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2179412
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://moodle.org/mod/forum/discuss.php?d=445062PatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2179412
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://moodle.org/mod/forum/discuss.php?d=445062PatchVendor Advisory
FAQ
What is CVE-2023-28330?
CVE-2023-28330 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
How severe is CVE-2023-28330?
CVE-2023-28330 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-28330?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.