The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
{ "nvd_published_at": "2023-05-02T20:15:10Z", "cwe_ids": [ "CWE-610", "CWE-73" ], "severity": "MODERATE", "github_reviewed": true, "github_reviewed_at": "2023-05-02T23:13:25Z" }