Record summary

CVE-2022-0332 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

A flaw was found in Moodle in versions 3.11 to 3.11.4. An SQL injection risk was identified in the h5p activity web service responsible for fetching user attempt data.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Affected products and versions

2
ProductSourceVersion rangeStatus

moodle

CVE Listmoodle 3.11.5affected
GitHub Advisory3.11 to < 3.11.5 · Fixed in 3.11.5affected

Proofs of concept

2

Catalogued exploits

ExploitDBMoodle 3.11.4 - SQL InjectionExploitDB exploitby lavclash75Not analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubnumanturle/CVE-2022-0332Repository PoCby numanturleStars: 46Not analyzed5 files

1.3 MiB

GitHub

PoC details

References

5