CVE-2023-28329

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
SQL Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
moodlemoodle
3.9.0 <
𝑥
< 3.9.20
moodlemoodle
3.11.0 <
𝑥
< 3.11.13
moodlemoodle
4.0.0 <
𝑥
< 4.0.7
moodlemoodle
3.9.0
moodlemoodle
3.11.0
moodlemoodle
4.0.0
moodlemoodle
4.1.0
moodlemoodle
4.1.1
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
moodlemoodle
- ≤
𝑥
< 3.9.20
ADP
moodlemoodle
3.11.0 ≤
𝑥
< 3.11.13
ADP
moodlemoodle
4.0.0 ≤
𝑥
< 4.0.7
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
moodle
bionic
needs-triage
focal
dne
jammy
dne
kinetic
dne
trusty
ignored
xenial
needs-triage