CVE-2009-4305

Moodle <1.8.11, <1.9.7 - SQL Injection

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in the SCORM module in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 allows remote authenticated users to execute arbitrary SQL commands via vectors related to an "escaping issue when processing AICC CRS file (Course_Title)."

References (9)

Core 9
Core References
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/3455
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/37614
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/37244
Patch, Vendor Advisory x_refsource_confirm
http://moodle.org/mod/forum/discuss.php?d=139120

Scores

EPSS 0.0084
EPSS Percentile 74.9%

Details

CWE
CWE-89
Status published
Products (15)
moodle/moodle 1.8.1
moodle/moodle 1.8.2
moodle/moodle 1.8.3
moodle/moodle 1.8.4
moodle/moodle 1.8.5
moodle/moodle 1.8.7
moodle/moodle 1.8.8
moodle/moodle 1.8.9
moodle/moodle 1.8.10
moodle/moodle 1.9.1
... and 5 more
Published Dec 16, 2009
Tracked Since Feb 18, 2026