CVE-2017-2641: SQL Injection
In Moodle 2.x and 3.x, SQL injection can occur via user preferences.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.2.2 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.1.5 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.0.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 2.7.19
Event History
Frequently Asked Questions
What is the severity of CVE-2017-2641?
The severity of CVE-2017-2641 is considered high due to the potential for SQL injection attacks affecting user preferences.
How do I fix CVE-2017-2641?
To fix CVE-2017-2641, update Moodle to versions 2.7.19, 3.0.9, 3.1.5, or 3.2.2 or later.
Which versions of Moodle are affected by CVE-2017-2641?
CVE-2017-2641 affects Moodle versions 2.7.0 to 2.7.18 and 3.0.0 to 3.2.0.
What type of vulnerability is CVE-2017-2641?
CVE-2017-2641 is categorized as an SQL injection vulnerability.
Can CVE-2017-2641 be exploited remotely?
Yes, CVE-2017-2641 can be exploited remotely by an attacker with access to user preference settings.