Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:34977
HistoryApr 06, 2022 - 3:19 a.m.

SQL Injection

2022-04-0603:19:42
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
27
sql injection
moodle
award_criteria_profile.php
software vulnerability
improper configuration

EPSS

0.001

Percentile

37.0%

moodle/moodle is vulnerable to sql injection. The vulnerability exists due to improper configuration in the get_options function of award_criteria_profile.php which allows an attacker to inject malicious sql queries.

EPSS

0.001

Percentile

37.0%