CVE-2022-30599: SQL Injection
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Other sources
An SQL injection risk was identified in Badges code relating to configuring criteria. NOTE: in Moodle 4.0, 3.11.6, 3.10.10 and 3.9.13, access to this vulnerability was available to site administrators only. In earlier versions, access to the relevant capability was also limited to teachers and managers by default.
Versions affected: 4.0, 3.11 to 3.11.6, 3.10 to 3.10.10, 3.9 to 3.9.13 and earlier unsupported versions Versions fixed : 4.0.1, 3.11.7, 3.10.11 and 3.9.14
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-30599?
The severity of CVE-2022-30599 is classified as a critical SQL injection vulnerability in Moodle.
How do I fix CVE-2022-30599?
To fix CVE-2022-30599, update your Moodle installation to version 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
Which versions of Moodle are affected by CVE-2022-30599?
Affected versions of Moodle include 3.9.x up to 3.9.13, 3.10.x up to 3.10.10, 3.11.x up to 3.11.6, and 4.0.0.
Is there a workaround for CVE-2022-30599?
There is no known workaround for CVE-2022-30599; updating to a fixed version is required.
What types of systems are impacted by CVE-2022-30599?
CVE-2022-30599 impacts Moodle instances configured with Badges code relating to configuring criteria.