Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7mmc-22g7-3xq2

Опубликовано: 02 мая 2023
Источник: github
Github: Прошло ревью
CVSS3: 7.3

Описание

Moodle SQL Injection vulnerability

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

< 4.2.0-rc2

4.2.0-rc2

EPSS

Процентиль: 73%
0.00793
Низкий

7.3 High

CVSS3

Дефекты

CWE-89

Связанные уязвимости

CVSS3: 5.6
ubuntu
около 2 лет назад

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

CVSS3: 5.6
nvd
около 2 лет назад

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

CVSS3: 5.6
debian
около 2 лет назад

The vulnerability was found Moodle which exists due to insufficient sa ...

CVSS3: 7.3
fstec
около 2 лет назад

Уязвимость виртуальной обучающей среды Moodle, связанная с недостаточной очисткой данных, позволяющая нарушителю выполнять произвольные SQL-запросы в базе данных

CVSS3: 9.8
redos
почти 2 года назад

Множественные уязвимости moodle

EPSS

Процентиль: 73%
0.00793
Низкий

7.3 High

CVSS3

Дефекты

CWE-89