๐Ÿ” CVE Alert

CVE-2023-28329

MEDIUM 6.3

Moodle: authenticated sql injection via availability check

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

CWE CWE-89
Published Mar 23, 2023
Last Updated Aug 2, 2024
Stay Ahead of the Next One

Get instant alerts for

Be the first to know when new medium vulnerabilities are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
bugzilla.redhat.com: https://bugzilla.redhat.com/show_bug.cgi?id=2179406 lists.fedoraproject.org: https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/ moodle.org: https://moodle.org/mod/forum/discuss.php?d=445061