CVE-2023-30943: Vulnerability Analysis & Exploit Details

Status: Modified - Last modified: 21-11-2024 Published: 02-05-2023

CVE-2023-30943
Vulnerability Scoring

6.5
/10

Attack Complexity Details

  • Attack Complexity: Low Impact
  • Attack Vector: NETWORK
  • Privileges Required: None
  • Scope: UNCHANGED
  • User Interaction: REQUIRED

CIA Impact Definition

  • Confidentiality:
  • Integrity: HIGH IMPACT
  • Availability:

CVE-2023-30943 Vulnerability Summary

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

Need help fixing CVEs? Check out our Step-by-Step Guide on How to Fix CVEs.

Access Complexity Graph for CVE-2023-30943

Impact Analysis for CVE-2023-30943

CVE-2023-30943: Detailed Information and External References

EPSS

0.01475

EPSS %

0.86576

References

0.01475

CWE

CWE-610

CAPEC

0.01475

  • XML Routing Detour Attacks: An attacker subverts an intermediate system used to process XML content and forces the intermediate to modify and/or re-route the processing of the content. XML Routing Detour Attacks are Adversary in the Middle type attacks (CAPEC-94). The attacker compromises or inserts an intermediate system in the processing of the XML message. For example, WS-Routing can be used to specify a series of nodes or intermediaries through which content is passed. If any of the intermediate nodes in this route are compromised by an attacker they could be used for a routing detour attack. From the compromised system the attacker is able to route the XML process to other nodes of their choice and modify the responses so that the normal chain of processing is unaware of the interception. This system can forward the message to an outside entity and hide the forwarding and processing from the legitimate processing systems by altering the header information.

Vulnerable Configurations

  • cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*
  • cpe:2.3:a:moodle:moodle:4.1.0:rc1:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.0:rc1:*:*:*:*:*:*
  • cpe:2.3:a:moodle:moodle:4.1.0:rc2:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.0:rc2:*:*:*:*:*:*
  • cpe:2.3:a:moodle:moodle:4.1.0:rc3:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.0:rc3:*:*:*:*:*:*
  • cpe:2.3:a:moodle:moodle:4.1.0:beta:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.0:beta:*:*:*:*:*:*
  • cpe:2.3:a:moodle:moodle:4.1.1:*:*:*:*:*:*:*
    cpe:2.3:a:moodle:moodle:4.1.1:*:*:*:*:*:*:*
  • cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:7.0:*:*:*:*:*:*:*
    cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:7.0:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
    cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
    cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*
  • cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
    cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*

CVSS3 Source

patrick@puiterwijk.org

CVSS3 Type

Secondary

CVSS3 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Protect Your Infrastructure: Combat Critical CVE Threats

Stay updated with real-time CVE vulnerabilities and take action to secure your systems. Enhance your cybersecurity posture with the latest threat intelligence and mitigation techniques. Develop the skills necessary to defend against CVEs and secure critical infrastructures. Join the top cybersecurity professionals safeguarding today's infrastructures.

Recently Published CVEs