PT-2023-25157 · Moodle+2 · Moodle+2

Paul Holden

·

Publicado

2020-11-08

·

Atualizado

2024-04-19

·

CVE-2023-35132

CVSS v3.1

6.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Moodle versions 3.9 to 3.9.21 Moodle versions 3.11 to 3.11.14 Moodle versions 4.0 to 4.0.8 Moodle versions 4.1 to 4.1.3 Moodle version 4.2
Description A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw is related to insufficient cleaning of user-provided data, which can be exploited by a remote attacker to read, delete, or modify data in the database and gain full control over the vulnerable application.
Recommendations For Moodle versions 3.9 to 3.9.21, update to a version that includes the fix for this issue. For Moodle versions 3.11 to 3.11.14, update to a version that includes the fix for this issue. For Moodle versions 4.0 to 4.0.8, update to a version that includes the fix for this issue. For Moodle versions 4.1 to 4.1.3, update to a version that includes the fix for this issue. For Moodle version 4.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the Mnet SSO access control page until a patch is available.

Correção

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALT-PU-2020-3235
ALT-PU-2020-3289
ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
BIT-MOODLE-2023-35132
CVE-2023-35132
GHSA-49MV-VFCP-8GG9

Produtos afetados

Alt Linux
Moodle
Red Os