CVE-2023-28329: Moodle: authenticated sql injection via availability check
Published Mar 17, 2023
·Updated
Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
Affected Software
16 affected componentsFixes available
redhat/moodle<4.1.2
4.1.2
redhat/moodle<4.0.7
4.0.7
redhat/moodle<3.11.13
3.11.13
redhat/moodle<3.9.20
3.9.20
composer/moodle/moodle<3.9.20
3.9.20
composer/moodle/moodle>=3.11.0<3.11.13
3.11.13
composer/moodle/moodle>=4.0.0<4.0.7
4.0.7
composer/moodle/moodle>=4.1.0<4.1.2
4.1.2
Moodle moodle>3.9.0<3.9.20
Moodle moodle>3.11.0<3.11.13
Moodle moodle>4.0.0<4.0.7
Moodle moodle=3.9.0
Moodle moodle=3.11.0
Moodle moodle=4.0.0
Moodle moodle=4.1.0
Moodle moodle=4.1.1
Remediation
Patch Available
Event History
Mar 17, 2023
Data Sourced
via Red Hat·05:35 PM
DescriptionSeverityAffected Software
Mar 23, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2023-28329.
2
What is the severity of CVE-2023-28329?
The severity of CVE-2023-28329 is high (8.8).
3
What software versions are affected by CVE-2023-28329?
Software versions between 3.9.0 and 3.9.20, 3.11.0 and 3.11.13, and 4.0.0 and 4.0.7 of Moodle are affected by CVE-2023-28329.
4
What is the CWE ID of CVE-2023-28329?
The CWE ID of CVE-2023-28329 is CWE-89.
5
How can I fix CVE-2023-28329?
To fix CVE-2023-28329, update your Moodle software to a version that is not affected by the vulnerability.