PT-2016-7433 · Moodle · Moodle

José Domingo Carrillo

·

Published

2016-10-28

·

Updated

2024-08-06

·

CVE-2016-7919

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Moodle version 3.1.2
Description The issue allows remote attackers to obtain sensitive information via unspecified vectors, related to a SQL Injection issue affecting the Administration panel function in the installation process component. The vendor disputes the relevance of this report, noting that the person installing Moodle must know database access credentials and they can access the database directly, thus there is no need for them to create a SQL injection in one of the installation dialogue fields.
Recommendations For Moodle version 3.1.2, consider restricting access to the Administration panel function in the installation process component to minimize the risk of exploitation. As a temporary workaround, avoid using the installation dialogue fields that may be vulnerable to SQL injection until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2016-7919

Affected Products

Moodle