CVE-2022-0983: SQL Injection
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-0983?
CVE-2022-0983 is an SQL injection vulnerability in the Badges code of Moodle.
Who is affected by CVE-2022-0983?
Users of Moodle versions 3.9.0 to 3.9.13, 3.10.0 to 3.10.10, and 3.11.0 to 3.11.6 are affected. Fedora versions 35 and 36, and Fedora Extra Packages for Enterprise Linux 7.0 are also affected.
What is the severity of CVE-2022-0983?
The severity of CVE-2022-0983 is rated as high, with a severity score of 8.8.
How can I fix CVE-2022-0983?
To fix CVE-2022-0983, users should upgrade to Moodle version 3.9.14, 3.10.11, or 3.11.7. Fedora users should update to the latest available package updates.
Where can I find more information about CVE-2022-0983?
More information about CVE-2022-0983 can be found at the following references: [Bugzilla Red Hat](https://bugzilla.redhat.com/show_bug.cgi?id=2064119), [Fedora Security](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/G4GRMWBGHOJMFXMTORECQNULJK7ZJJ6Y/), [Moodle Git](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-74074).