Lucene search

K
osvGoogleOSV:GHSA-H2FW-93QX-VRCQ
HistoryMar 26, 2022 - 12:00 a.m.

SQL Injection in Moodle

2022-03-2600:00:29
Google
osv.dev
25
sql injection
moodle
badges
criteria configuration
teachers
managers
software

EPSS

0.001

Percentile

37.0%

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

EPSS

0.001

Percentile

37.0%