S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2023-30943 Scanner

Detects 'Cross-Site Scripting (XSS)' vulnerability in Moodle affects v. from  4.1 to 4.1.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.7k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-30943
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
AFFECTED< 4.1.3SAFE ✓≥ 4.1.3
Updated Aug 22, 2026View on NVD →
Detail

Moodle is an open-source learning management system that is used by educational institutions and businesses of all sizes around the world. It was created to provide a secure, scalable, and customizable platform for online learning, allowing organizations to create and deliver engaging courses, track student progress, and manage their learning activities.

However, Moodle is not immune to security vulnerabilities, and recently, a new CVE-2023-30943 vulnerability has been discovered in the platform. This vulnerability exists because the application allows a user to control the path of the older to create in TinyMCE loaders. This means that a remote user can send a specially crafted HTTP request and create arbitrary folders on the system.

This vulnerability can have severe consequences when exploited. A remote attacker with access to this vulnerability can create arbitrary folders on the system, which can be used as a launching point for other attacks. This can allow attackers to create backdoors, escalate their privileges, and even gain complete control over the system. In the worst-case scenario, this can result in data theft, system crashes, or even a complete system compromise.

If you want to stay on top of the latest vulnerabilities and threats to your digital assets, you can rely on the pro features of the s4e.io platform. With our platform, you can easily and quickly learn about vulnerabilities in your digital assets, get expert guidance on remediation, and gain peace of mind knowing that your assets are protected against emerging threats. So, what are you waiting for? Sign up for s4e.io now and protect your digital assets today!

 

REFERENCES

Solution Advice

Fortunately, there are precautions that can be taken to protect against this vulnerability. These include:

  • Updating Moodle to the latest version
  • Configuring the server to deny access to unknown file types or folders
  • Disabling unused plugins and modules
  • Limiting user privileges in Moodle
  • Regularly performing security audits and vulnerability scans

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2023-30943 scanner - Cross-Site Scripting (XSS) vulnerability in Moodle | S4E