Moodle Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2017-2641 - Vulnerability Database

Moodle Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2017-2641

Critical
Reference: CVE-2017-2641
Title: Moodle Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability
Overview:

In Moodle 2.x and 3.x SQL injection can occur via user preferences.