Boletines de Vulnerabilidades

MSA-23-0014: TinyMCE loaders susceptible to Arbitrary Folder Creation


Información sobre el sistema

   
Software afectado PHP

Descripción

par Michael Hawkins. Insufficient sanitizing of loaders used by TinyMCE resulted in an arbitrary folder creation risk.Severity/Risk:SeriousVersions affected:4.1 to 4.1.2Versions fixed:4.1.3Reported by:Yaniv Nizry (SonarSource)CVE identifier:CVE-2023-30943Changes (master):http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-77718Tracker issue:MDL-77718 TinyMCE loaders susceptible to Arbitrary Folder Creation

More info:

https://moodle.org/mod/forum/discuss.php?d=446285&parent=1793613

Identificadores estándar

Propiedad Valor
CVE CVE-2023-30943.

Histórico de versiones

Versión Comentario Fecha
1.0 Advisory issued 2023-06-22

Miembros de

Ministerio de Defensa
CNI
CCN
CCN-CERT