First published: Fri Dec 31 2004(Updated: )
SQL injection vulnerability in sql.php in the Glossary module in Moodle 1.4.1 and earlier allows remote attackers to modify SQL statements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle | =1.2.1 | |
Moodle | =1.3.3 | |
Moodle | =1.3.2 | |
Moodle | =1.1.1 | |
Moodle | =1.3.1 | |
Moodle | =1.4.1 | |
Moodle | =1.3.4 | |
Moodle | =1.2.0 | |
Moodle | =1.3.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2232 has been rated as a medium severity vulnerability due to its impact on SQL statement modification.
To fix CVE-2004-2232, upgrade Moodle to version 1.4.2 or later, which mitigates the SQL injection vulnerability.
CVE-2004-2232 allows remote attackers to manipulate SQL statements, potentially leading to data leakage or unauthorized data modification.
CVE-2004-2232 affects Moodle versions 1.4.1 and earlier, including versions 1.3.x and 1.2.x.
Yes, CVE-2004-2232 is specifically an SQL injection vulnerability located in the Glossary module of Moodle.