← back
CVE-2023-28330mediumCWE-20

Moodle: authenticated arbitrary file read through malformed backup file

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 1.2%
exploitation probability
1.2%top 34% of all CVEs
observed exploitation
nono source reports it
Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Affected products
moodle