Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:4628
HistoryJul 21, 2017 - 8:32 a.m.

SQL Injection

2017-07-2108:32:00
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16

EPSS

0.001

Percentile

51.1%

Moodle is vulnerable to SQL injection attacks. The attacks exist because the application does not filter null bytes \0 characters in query strings, leading to SQL statements failing and causing error to the Microsoft SQL driver. This can allow a malicious user to inject and execute SQL queries.

EPSS

0.001

Percentile

51.1%