Moodle是一套免费、开源的电子学习软件平台,也称课程管理系统、学习管理系统或虚拟学习环境。 Moodle存在安全漏洞,该漏洞源于允许用户控制要在TinyMCE加载程序中创建的旧文件的路径,远程用户可以发送特制的HTTP请求并在系统上创建任意文件夹。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | CVE-2023-30943 RCE PoC | https://github.com/d0rb/CVE-2023-30943 | POC Details |
| 2 | A Python-based tool to detect the CVE-2023-30943 vulnerability in Moodle, which allows unauthorized folder creation via specially crafted requests in TinyMCE loaders. | https://github.com/Chocapikk/CVE-2023-30943 | POC Details |
| 3 | CVE-2023-30943 (Moodle XSS) | https://github.com/RubyCat1337/CVE-2023-30943 | POC Details |
| 4 | The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system. Moodle versions 4.1.x before 4.1.3 and 4.2.x before 4.2.0 are susceptible to an unauthenticated arbitrary folder creation, tracked as CVE-2023-30943. An attacker can leverage the creation of arbitrary folders to carry out a Stored Cross-Site Scripting (XSS) attack on the administration panel, resulting in arbitrary code execution on the server as soon as an administrator visits the panel. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-30943.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet