PT-2016-7433 · Moodle · Moodle
José Domingo Carrillo
·
Published
2016-10-28
·
Updated
2024-08-06
·
CVE-2016-7919
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Moodle version 3.1.2
Description
The issue allows remote attackers to obtain sensitive information via unspecified vectors, related to a SQL Injection issue affecting the Administration panel function in the installation process component. The vendor disputes the relevance of this report, noting that the person installing Moodle must know database access credentials and they can access the database directly, thus there is no need for them to create a SQL injection in one of the installation dialogue fields.
Recommendations
For Moodle version 3.1.2, consider restricting access to the Administration panel function in the installation process component to minimize the risk of exploitation. As a temporary workaround, avoid using the installation dialogue fields that may be vulnerable to SQL injection until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Moodle