CVE-2023-30944: Fedoraproject Extra Packages For Enterprise Linux
High severity, CVSS 7.3. EPSS: 1.1% chance of exploitation in the next 30 days.
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
Affected products
- Fedoraproject Extra Packages For Enterprise Linux: version 7.0 only
- Fedoraproject Fedora: version 36 only; version 37 only; version 38 only
- Moodle Moodle: from 3.9.0, before 3.9.21 (fixed in 3.9.21); from 3.11.0, before 3.11.14 (fixed in 3.11.14); from 4.0.0, before 4.0.8 (fixed in 4.0.8); from 4.1.0, before 4.1.3 (fixed in 4.1.3)
Published 2023-05-02. Last modified 2026-06-17.