Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T02:13:20.936Z
Reserved: 2016-09-09T00:00:00
Link: CVE-2016-7919
Updated: 2024-08-06T02:13:20.936Z
Status : Deferred
Published: 2016-10-28T15:59:00.170
Modified: 2025-04-12T10:46:40.837
Link: CVE-2016-7919
No data.
OpenCVE Enrichment
No data.