The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
- | 4.2.0-rc2 |
moodle / moodle
|
4.1.0 | 4.1.3 |
| fedoraproject / fedora | 36 | 36.x |
| fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |
| fedoraproject / fedora | 37 | 37.x |
| fedoraproject / fedora | 38 | 38.x |