vulnerability

Moodle: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CVE-2023-28329)

Severity
9
CVSS
(AV:N/AC:L/Au:S/C:C/I:C/A:C)
Published
Mar 23, 2023
Added
Mar 29, 2023
Modified
Jan 28, 2025

Description

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

Solution(s)

moodle-upgrade-3_11_13moodle-upgrade-3_9_20moodle-upgrade-4_0_7
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.