The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
{
"cwe_ids": [
"CWE-610",
"CWE-73"
],
"github_reviewed": true,
"github_reviewed_at": "2023-05-02T23:13:25Z",
"nvd_published_at": "2023-05-02T20:15:10Z",
"severity": "MODERATE"
}