The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
| Software | From | Fixed in |
|---|---|---|
moodle / moodle
|
- | 4.2.0-rc2 |
moodle / moodle
|
4.1.0 | 4.1.3 |
moodle / moodle
|
4.0.0 | 4.0.8 |
moodle / moodle
|
3.11.0 | 3.11.14 |
moodle / moodle
|
3.9.0 | 3.9.21 |
| fedoraproject / fedora | 36 | 36.x |
| fedoraproject / extra_packages_for_enterprise_linux | 7.0 | 7.0.x |
| fedoraproject / fedora | 37 | 37.x |
| fedoraproject / fedora | 38 | 38.x |