Untriaged
Moodle: authenticated sql injection via availability check
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
Affected products
moodle
- <4.0.7
- <3.11.13
- <4.1.2
- <3.9.20
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>