PT-2022-2689 · Moodle+2 · Moodle+2

Michael Dunstan

·

Published

2022-03-31

·

Updated

2024-03-06

·

CVE-2022-30599

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moodle (affected versions not specified)
Description A flaw was found in Moodle where an SQL injection risk was identified in Badges code relating to configuring criteria. The vulnerability is related to insufficient sanitization of user input in the badges code, allowing a remote attacker to execute arbitrary SQL code by sending a specially crafted request. This can enable the attacker to execute arbitrary commands in the application's database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2022-2502
ALT-PU-2022-2553
BDU:2022-03179
BIT-MOODLE-2022-30599
CVE-2022-30599
GHSA-69C3-5XXF-58Q2

Affected Products

Alt Linux
Moodle
Red Os