#VU67470 SQL injection in Moodle - CVE-2022-40315
Published: September 19, 2022
Moodle
moodle.org
Description
The vulnerability allows a remote user to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data in the "browse list of users" site administration page. A remote user can send a specially crafted request to the affected application and execute arbitrary SQL commands within the application database.