CVE-2023-30943: Fedoraproject Extra Packages For Enterprise Linux

Medium severity, CVSS 5.3. EPSS: 6.6% chance of exploitation in the next 30 days.

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

Affected products

  • Fedoraproject Extra Packages For Enterprise Linux: version 7.0 only
  • Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
  • Moodle Moodle: from 4.1.0, before 4.1.3 (fixed in 4.1.3)

Published 2023-05-02. Last modified 2026-06-17.