Moodle is vulnerable to Improper Input Validation in MoodleQuickForm class
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Jan 23, 2024
Package
Affected versions
>= 2.3.0, < 2.3.7
>= 2.4.0, < 2.4.4
< 2.2.10
Patched versions
2.3.7
2.4.4
2.2.10
Description
Published by the National Vulnerability Database
May 25, 2013
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Aug 17, 2023
Last updated
Jan 23, 2024
The MoodleQuickForm class in
lib/formslib.php
in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which allows remote attackers to bypass intended form-data filtering via a crafted request.References