Lucene search

K
osvGoogleOSV:GHSA-7H8V-2V8X-H264
HistoryMar 29, 2021 - 8:42 p.m.

SQL Injection in moodle

2021-03-2920:42:19
Google
osv.dev
14
moodle
sql injection
vulnerability
database module
web services
students
groups
versions affected
fixed
software

EPSS

0.001

Percentile

47.6%

In moodle, some database module web services allowed students to add entries within groups they did not belong to. Versions affected: 3.9 to 3.9.2, 3.8 to 3.8.5, 3.7 to 3.7.8, 3.5 to 3.5.14 and earlier unsupported versions. This is fixed in moodle 3.8.6, 3.7.9, 3.5.15, and 3.10.

EPSS

0.001

Percentile

47.6%