CVE-2023-28330

MEDIUM6.5EPSS 1.0%

Moodle: authenticated arbitrary file read through malformed backup file

發布日:2023/3/23修改日:2025/5/20

描述

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1MEDIUM6.5CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

參考連結(9)