Description
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Remediation
References
Related Vulnerabilities
MySQL CVE-2015-4815 Vulnerability (CVE-2015-4815)
WordPress Plugin Nextend Facebook Connect Cross-Site Scripting (1.5.5)
WordPress Plugin ARForms:Wordpress Form Builder Arbitrary File Deletion (3.5.1)
Handlebars Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2019-20920)