CVE-2023-5540
published 2023-11-09CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
PriorityP359high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
1.93%
77.8th percentile
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | < 3.9.24 | 3.9.24 |
| moodle | moodle | >= 0 < 4.3.0-rc2 | 4.3.0-rc2 |
| moodle | moodle | >= 3.11.0 < 3.11.17 | 3.11.17 |
| moodle | moodle | >= 4.0.0 < 4.0.11 | 4.0.11 |
| moodle | moodle | >= 4.1.0 < 4.1.6 | 4.1.6 |
| moodle | moodle | >= 4.2.0 < 4.2.3 | 4.2.3 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moodle Code Injection vulnerability
osv·2023-11-09
CVE-2023-5540 [HIGH] Moodle Code Injection vulnerability
Moodle Code Injection vulnerability
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
GHSA
Moodle Code Injection vulnerability
ghsa·2023-11-09
CVE-2023-5540 [HIGH] CWE-94 Moodle Code Injection vulnerability
Moodle Code Injection vulnerability
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
OSV
CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity
osv·2023-11-09·CVSS 8.8
CVE-2023-5540 [HIGH] CVE-2023-5540: A remote code execution risk was identified in the IMSCP activity
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79409https://bugzilla.redhat.com/show_bug.cgi?id=2243432https://moodle.org/mod/forum/discuss.php?d=451581http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79409https://bugzilla.redhat.com/show_bug.cgi?id=2243432https://moodle.org/mod/forum/discuss.php?d=451581
2023-11-09
Published