Miggo Logo

CVE-2023-35132: Moodle vulnerable to SQL Injection

6.3

CVSS Score
3.1

Basic Information

EPSS Score
0.43396%
Published
6/22/2023
Updated
4/19/2024
KEV Status
No
Technology
TechnologyPHP

Technical Details

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Package NameEcosystemVulnerable VersionsFirst Patched Version
moodle/moodlecomposer= 4.2.04.2.1
moodle/moodlecomposer>= 4.1.0, < 4.1.44.1.4
moodle/moodlecomposer>= 4.0.0, < 4.0.94.0.9
moodle/moodlecomposer>= 3.10.0, < 3.11.153.11.15
moodle/moodlecomposer< 3.9.223.9.22

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

* limit** SQL inj**tion risk w*s i**nti*i** on t** Mn*t SSO ****ss *ontrol p***. T*is *l*w *****ts Moo*l* v*rsions *.*, *.* to *.*.*, *.* to *.*.*, *.** to *.**.**, *.* to *.*.** *n* **rli*r unsupport** v*rsions.

Reasoning

No *n*lysis *v*il**l*