Loading HuntDB...

GHSA-h2fw-93qx-vrcq

GitHub Security Advisory

SQL Injection in Moodle

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

Affected Packages

Packagist moodle/moodle
Affected versions: 3.11.0 (fixed in 3.11.6)
Packagist moodle/moodle
Affected versions: 3.10.0 (fixed in 3.10.10)
Packagist moodle/moodle
Affected versions: 0 (fixed in 3.9.13)

Related CVEs

Key Information

GHSA ID
GHSA-h2fw-93qx-vrcq
Published
March 26, 2022 12:00 AM
Last Modified
April 1, 2022 6:03 PM
CVSS Score
7.5 /10
Primary Ecosystem
Packagist
Primary Package
moodle/moodle
GitHub Reviewed
✓ Yes

Dataset

Last updated: June 15, 2025 6:24 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.