An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
3.9.0 | 3.9.13 |
| fedoraproject / fedora | 35 | 35.x |
| fedoraproject / fedora | 36 | 36.x |
| fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |
moodle / moodle
|
3.11.0 | 3.11.6 |
moodle / moodle
|
3.10.0 | 3.10.10 |
moodle / moodle
|
- | 3.9.13 |