Description
The vulnerability was found Moodle which exists because the application allows a user to control path of the older to create in TinyMCE loaders. A remote user can send a specially crafted HTTP request and create arbitrary folders on the system.
Remediation
References
Related Vulnerabilities
Django Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2011-4140)
Drupal Improper Input Validation Vulnerability (CVE-2016-9452)
WordPress Plugin Advanced Custom Fields:Table Field Cross-Site Scripting (1.1.12)
Apache HTTP Server CVE-2013-2249 Vulnerability (CVE-2013-2249)
WordPress Plugin Livemesh Addons for Elementor Security Bypass (2.5.2)