First published: Mon Jun 12 2023(Updated: )
A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | <3.9.22 | |
Moodle Moodle | >=3.11.0<3.11.15 | |
Moodle Moodle | >=4.0.0<4.0.9 | |
Moodle Moodle | >=4.1.0<4.1.4 | |
Moodle Moodle | =4.2.0 | |
composer/moodle/moodle | <3.9.22 | 3.9.22 |
composer/moodle/moodle | >=3.10.0<3.11.15 | 3.11.15 |
composer/moodle/moodle | >=4.0.0<4.0.9 | 4.0.9 |
composer/moodle/moodle | >=4.1.0<4.1.4 | 4.1.4 |
composer/moodle/moodle | =4.2.0 | 4.2.1 |
redhat/moodle | <4.2.1 | 4.2.1 |
redhat/moodle | <4.1.4 | 4.1.4 |
redhat/moodle | <4.0.9 | 4.0.9 |
redhat/moodle | <3.11.15 | 3.11.15 |
redhat/moodle | <3.9.22 | 3.9.22 |
<3.9.22 | ||
>=3.11.0<3.11.15 | ||
>=4.0.0<4.0.9 | ||
>=4.1.0<4.1.4 | ||
=4.2.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-35132 is a vulnerability that allows for limited SQL injection on the Mnet SSO access control page in Moodle.
Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21, and earlier unsupported versions are affected by CVE-2023-35132.
CVE-2023-35132 has a severity rating of 6.3, which is considered medium.
CVE-2023-35132 allows an attacker to execute limited SQL injection attacks on the Mnet SSO access control page in Moodle.
Yes, patches have been released to fix CVE-2023-35132. It is recommended to update to the latest version of Moodle.