Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:37390
HistoryOct 03, 2022 - 9:24 a.m.

SQL Injection

2022-10-0309:24:28
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
17
moodle
sql injection
get_users_listing
datalib.php
sort helper
column mapping
malicious queries
software

EPSS

0.002

Percentile

52.2%

moodle/moodle is vulnerable to sql injection attacks. The vulnerability exists in get_users_listing function of datalib.php due to improper implementation of sort helper and column mapping for sort which allows an attacker to inject malicious queries into the system.

EPSS

0.002

Percentile

52.2%