CVE-2023-28329
Description
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
CWE
- CWE-89 — Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Affected
- / — v=4.1.0 <4.1.2 [affected]; v=4.0.0 <4.0.7 [affected]; v=3.11.0 <3.11.13 [affected]; v=0 <3.9.20 [affected]
CVSS
- (none)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2179406 issue-tracking, x_refsource_REDHAT
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3QZN34VSF4HTCW3C3ZP2OZYSLYUKADPF/ vendor-advisory
- https://moodle.org/mod/forum/discuss.php?d=445061
Source
cvelistV5-main/cves/2023/28xxx/CVE-2023-28329.json