PT-2022-5110 · Moodle+2 · Moodle+2

Vincent

·

Published

2020-11-08

·

Updated

2025-05-20

·

CVE-2022-40315

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle versions (affected versions not specified)
Description A limited SQL injection risk was identified in the "browse list of users" site administration page. The vulnerability is related to insufficient cleaning of user data on this page. Exploitation of the vulnerability may allow a remote attacker to execute arbitrary SQL commands by sending a specially crafted request.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2020-3235
ALT-PU-2023-2012
ALT-PU-2023-2057
ALT-PU-2023-5127
BDU:2022-06359
BIT-MOODLE-2022-40315
CVE-2022-40315
GHSA-MQW9-3CJM-XWP3

Affected Products

Alt Linux
Moodle
Red Os