Moodle Improper Neutralization of Special Elements used in an SQL Command (SQL Injection) Vulnerability - CVE-2017-2641
In Moodle 2.x and 3.x SQL injection can occur via user preferences.
In Moodle 2.x and 3.x SQL injection can occur via user preferences.