PT-2022-2037 · Fedoraproject+2 · Extra Packages For Enterprise Linux+3

Tej Rathi

·

Published

2022-03-14

·

Updated

2024-03-06

·

CVE-2022-0983

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified) fedoraproject extra packages for enterprise linux (affected versions not specified) fedoraproject fedora (affected versions not specified)
Description The issue is related to a lack of protection against SQL query structure exploitation, allowing a remote attacker to execute arbitrary SQL queries in the database. An SQL injection risk was identified in Badges code, specifically in configuring criteria, with access limited to teachers and managers by default.
Recommendations For Moodle, consider restricting access to the Badges code configuring criteria capability to minimize the risk of exploitation. For fedoraproject extra packages for enterprise linux and fedoraproject fedora, at the moment, there is no information about a newer version that contains a fix for this issue. As a temporary workaround, consider disabling the SQL query execution functionality in the affected components until a patch is available.

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-1476
ALT-PU-2022-2450
BDU:2022-01636
BIT-MOODLE-2022-0983
CVE-2022-0983
GHSA-H2FW-93QX-VRCQ

Affected Products

Alt Linux
Red Os
Extra Packages For Enterprise Linux
Fedora