Description
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Remediation
References
Related Vulnerabilities
ownCloud Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2014-3836)
OpenSSL Resource Management Errors Vulnerability (CVE-2011-3210)
WordPress Plugin YOP Poll Cross-Site Scripting (6.1.4)
WordPress Plugin WP Last Modified Info Cross-Site Scripting (1.6.5)
TYPO3 Improper Authentication Vulnerability (CVE-2023-47127)