PT-2022-2037 · Fedoraproject+2 · Extra Packages For Enterprise Linux+3
Tej Rathi
·
Published
2022-03-14
·
Updated
2024-03-06
·
CVE-2022-0983
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Moodle (affected versions not specified)
fedoraproject extra packages for enterprise linux (affected versions not specified)
fedoraproject fedora (affected versions not specified)
Description
The issue is related to a lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries in the database. An SQL injection risk was identified in Badges code, specifically in configuring criteria, with access limited to teachers and managers by default.
Recommendations
For Moodle, consider restricting access to the Badges code configuring criteria capability to minimize the risk of exploitation.
For fedoraproject extra packages for enterprise linux and fedoraproject fedora, at the moment, there is no information about a newer version that contains a fix for this issue.
As a temporary workaround, consider disabling the SQL query execution functionality in the affected components until a patch is available.
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Os
Extra Packages For Enterprise Linux
Fedora