First published: Tue May 10 2022(Updated: )
A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.9<3.9.14 | 3.9.14 |
composer/moodle/moodle | >=3.10<3.10.11 | 3.10.11 |
composer/moodle/moodle | >=3.11<3.11.7 | 3.11.7 |
composer/moodle/moodle | >=4.0<4.0.1 | 4.0.1 |
redhat/moodle | <4.0.1 | 4.0.1 |
redhat/moodle | <3.11.7 | 3.11.7 |
redhat/moodle | <3.10.11 | 3.10.11 |
redhat/moodle | <3.9.14 | 3.9.14 |
Moodle | >=3.9<3.9.14 | |
Moodle | >=3.10<3.10.11 | |
Moodle | >=3.11<3.11.7 | |
Moodle | =4.0.0 | |
Red Hat Enterprise Linux | =8.0 | |
Fedora | =34 | |
Fedora | =35 | |
Fedora | =36 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-30599 is classified as a critical SQL injection vulnerability in Moodle.
To fix CVE-2022-30599, update your Moodle installation to version 3.9.14, 3.10.11, 3.11.7, or 4.0.1.
Affected versions of Moodle include 3.9.x up to 3.9.13, 3.10.x up to 3.10.10, 3.11.x up to 3.11.6, and 4.0.0.
There is no known workaround for CVE-2022-30599; updating to a fixed version is required.
CVE-2022-30599 impacts Moodle instances configured with Badges code relating to configuring criteria.