Untriaged
Moodle: minor sql injection risk in external wiki method for listing pages
The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
Affected products
moodle
- <3.11.14
- <4.0.8
- <3.9.21
- <4.1.3
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>