Looking for the vulnerability index of Invicti's legacy products?
Moodle Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-28329) - Vulnerability Database

Moodle Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Vulnerability (CVE-2023-28329)

Description

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

References

Related Vulnerabilities