CVE-2023-28330

CVE-2023-28330: Moodle: authenticated arbitrary file read through malformed backup file

Weakness CWE-20 · Input validation
Published March 23, 2023
Last update August 2, 2024

CVSS base score

What the vulnerability does

01Description

Insufficient sanitizing in backup resulted in an arbitrary file read risk. The capability to access this feature is only available to teachers, managers and admins by default.

Key dates

02Disclosure timeline

March 23, 2023 CVE published
August 2, 2024 Record updated