CVE-2023-28329

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
23/03/2023
Last modified:
03/07/2024

Description

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.9.0 (excluding) 3.9.20 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 3.11.0 (excluding) 3.11.13 (excluding)
cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* 4.0.0 (excluding) 4.0.7 (excluding)
cpe:2.3:a:moodle:moodle:3.9.0:-:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:3.11.0:-:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:4.0.0:-:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:4.1.0:-:*:*:*:*:*:*
cpe:2.3:a:moodle:moodle:4.1.1:*:*:*:*:*:*:*