CVE-2023-30944

HIGH7.3EPSS 1.1%

Moodle SQL Injection vulnerability

發布日:2023/5/2修改日:2024/4/19
也稱為:GHSA-7mmc-22g7-3xq2BIT-moodle-2023-30944

描述

The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.

受影響套件(2)

CVSS 分數

來源版本嚴重程度向量
osvCVSS 3.1HIGH7.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

參考連結(15)