CVE-2023-35132: Moodle: minor sql injection risk on mnet sso access control page
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 4.0.9 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.11.15 - Upgrade
Upgrade
redhat/moodleto a version that resolves this vulnerability.Fixed in 3.9.22 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.9.22 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 3.11.15 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.0.9 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.1.4 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.2.1 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 4.0.9 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.11.15 - Upgrade
Upgrade
Moodleto a version that resolves this vulnerability.Fixed in 3.9.22
Event History
Frequently Asked Questions
What is CVE-2023-35132?
CVE-2023-35132 is a vulnerability that allows for limited SQL injection on the Mnet SSO access control page in Moodle.
Which versions of Moodle are affected by CVE-2023-35132?
Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21, and earlier unsupported versions are affected by CVE-2023-35132.
What is the severity of CVE-2023-35132?
CVE-2023-35132 has a severity rating of 6.3, which is considered medium.
How does CVE-2023-35132 work?
CVE-2023-35132 allows an attacker to execute limited SQL injection attacks on the Mnet SSO access control page in Moodle.
Is there a fix for CVE-2023-35132?
Yes, patches have been released to fix CVE-2023-35132. It is recommended to update to the latest version of Moodle.