PT-2024-8616 · Moodle+2 · Moodle+2

Taiyou

·

Published

2024-08-19

·

Updated

2025-08-06

·

CVE-2024-43436

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Moodle versions (affected versions not specified)
Description A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. This issue is related to the lack of protection against SQL query structure exploitation, which may allow a remote attacker to execute arbitrary SQL queries in the database.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

SQL injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-16385
ALT-PU-2024-16417
BDU:2024-10190
BIT-MOODLE-2024-43436
CVE-2024-43436
GHSA-MX26-62XM-2P83

Affected Products

Alt Linux
Moodle
Red Os