CVE-2023-5540: Moodle: authenticated remote code execution risk in imscp
Published Oct 11, 2023
·Updated
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
Affected Software
13 affected componentsFixes available
composer/moodle/moodle<4.3.0-rc2
4.3.0-rc2
redhat/moodle<4.2.3
4.2.3
redhat/moodle<4.1.6
4.1.6
redhat/moodle<4.0.11
4.0.11
redhat/moodle<3.11.17
3.11.17
redhat/moodle<3.9.24
3.9.24
Moodle moodle<3.9.24
Moodle moodle>=3.11.0<3.11.17
Moodle moodle>=4.0.0<4.0.11
Moodle moodle>=4.1.0<4.1.6
Moodle moodle>=4.2.0<4.2.3
Fedoraproject Extra Packages For Enterprise Linux=7.0
Fedoraproject Fedora=38
Remediation
Patch Available
Patch Available
Event History
Nov 9, 2023
CVE Published
via MITRE·07:15 PM
Data Sourced
via MITRE·07:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-5540?
CVE-2023-5540 is a vulnerability that allows for authenticated remote code execution in imscp.
2
Who is affected by CVE-2023-5540?
Users of Moodle versions 3.9.24 to 4.2.3 and Moodle/Moodle versions 3.9.24 to 4.3.0-rc2 are affected by CVE-2023-5540.
3
How severe is CVE-2023-5540?
CVE-2023-5540 has a severity rating of 8.8, which is classified as high.
4
How can I fix the CVE-2023-5540 vulnerability?
To fix CVE-2023-5540, you should update your Moodle installation to version 4.2.3 or higher.
5
Where can I find more information about CVE-2023-5540?
More information about CVE-2023-5540 can be found in the references section of the vulnerability report.