bugzilla.redhat.com
https://bugzilla.redhat.com/show_bug.cgi?id=2043661 CVE-2022-0332
CRITICAL
SQL injection in Moodle
Record summary
CVE-2022-0332 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
moodle | CVE List | moodle 3.11.5 | affected |
moodle/moodleBrowse Packagist / moodle/moodle | GitHub Advisory | 3.11 to < 3.11.5 · Fixed in 3.11.5 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBMoodle 3.11.4 - SQL InjectionExploitDB exploitby lavclash75Not analyzed1 file
Repository PoCs
GitHubnumanturle/CVE-2022-0332Repository PoCby numanturleStars: 46Not analyzed5 files
References
5github.com
https://github.com/moodle/moodle github.com
https://github.com/moodle/moodle/commit/c7a62a8c82219b50589257f79021da1df1a76808 moodle.org
https://moodle.org/mod/forum/discuss.php?d=431099 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-0332