CVE-2023-28329
23.03.2023, 21:15
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
| Vendor | Product | Version |
|---|---|---|
| moodle | moodle | 3.9.0 < 𝑥 < 3.9.20 |
| moodle | moodle | 3.11.0 < 𝑥 < 3.11.13 |
| moodle | moodle | 4.0.0 < 𝑥 < 4.0.7 |
| moodle | moodle | 3.9.0 |
| moodle | moodle | 3.11.0 |
| moodle | moodle | 4.0.0 |
| moodle | moodle | 4.1.0 |
| moodle | moodle | 4.1.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
References