CVE-2013-4313 Information
Feb 14, 2021
cve
Description
Moodle through 2.2.11 2.3.x before 2.3.9 2.4.x before 2.4.6 and 2.5.x before 2.5.2 does not prevent use of ‘\0’ characters in query strings which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.
Reference
http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-40676 https://moodle.org/mod/forum/discuss.php?d=238396
Share on: