CVE-2023-5539: Moodle: authenticated remote code execution risk in lesson
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2023-5539?
CVE-2023-5539 is a vulnerability that allows authenticated remote code execution in the Lesson activity in Moodle.
What is the severity of CVE-2023-5539?
CVE-2023-5539 has a severity rating of 8.8 (high).
Which versions of Moodle are affected by CVE-2023-5539?
Moodle versions up to and including 4.2.3 are affected by CVE-2023-5539.
How can I fix CVE-2023-5539?
To fix CVE-2023-5539, you should update Moodle to version 4.2.3 or apply the relevant security patch.
Where can I find more information about CVE-2023-5539?
You can find more information about CVE-2023-5539 in the references provided: [http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79408](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-79408), [https://bugzilla.redhat.com/show_bug.cgi?id=2243352](https://bugzilla.redhat.com/show_bug.cgi?id=2243352), [https://moodle.org/mod/forum/discuss.php?d=451580](https://moodle.org/mod/forum/discuss.php?d=451580).