CVE-2023-5540

CWE-94Code Injection5 documents4 sources
Severity
8.8HIGH
EPSS
2.0%
top 16.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9

Description

A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:LExploitability: 1.2 | Impact: 3.4

Affected Packages3 packages

NVDmoodle/moodle3.11.03.11.17+4
Packagistmoodle/moodle< 4.3.0-rc2

Also affects: Fedora 38

Patches

🔴Vulnerability Details

4
CVEList
Moodle: authenticated remote code execution risk in imscp2023-11-09
OSV
Moodle Code Injection vulnerability2023-11-09
GHSA
Moodle Code Injection vulnerability2023-11-09
OSV
CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity2023-11-09