CVE-2023-5550: Moodle: rce due to lfi risk in some misconfigured shared hosting environments
Published Oct 12, 2023
·Updated
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve remote code execution.
Affected Software
18 affected componentsFixes available
composer/moodle/moodle<3.9.24
3.9.24
composer/moodle/moodle>=3.10.0<3.11.17
3.11.17
composer/moodle/moodle>=4.0.0<4.0.11
4.0.11
composer/moodle/moodle>=4.1.0<4.1.6
4.1.6
composer/moodle/moodle>=4.2.0<4.2.3
4.2.3
composer/moodle/moodle>=4.3.0-beta<4.3.0-rc2
4.3.0-rc2
redhat/moodle<4.2.3
4.2.3
redhat/moodle<4.1.6
4.1.6
redhat/moodle<4.0.11
4.0.11
redhat/moodle<3.11.17
3.11.17
redhat/moodle<3.9.24
3.9.24
Moodle moodle<3.9.24
Moodle moodle>=3.11.0<3.11.17
Moodle moodle>=4.0.0<4.0.11
Moodle moodle>=4.1.0<4.1.6
Moodle moodle>=4.2.0<4.2.3
Fedoraproject Extra Packages For Enterprise Linux=7.0
Fedoraproject Fedora=38
Remediation
Patch Available
Event History
Nov 9, 2023
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Advisory Published
09:30 PM
Frequently Asked Questions
1
What is CVE-2023-5550?
CVE-2023-5550 is a vulnerability that allows remote code execution in misconfigured shared hosting environments.
2
What is the severity of CVE-2023-5550?
CVE-2023-5550 has a severity rating of 9.8 (critical).
3
How can CVE-2023-5550 be exploited?
CVE-2023-5550 can be exploited through a local file include vulnerability in a misconfigured shared hosting environment.
4
Which versions of Moodle are affected by CVE-2023-5550?
Versions up to and including Moodle 4.2.3 are affected by CVE-2023-5550.
5
How can I fix CVE-2023-5550?
To fix CVE-2023-5550, update Moodle to version 4.2.4 or later.