Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-3286 | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. |
Github GHSA |
GHSA-mx26-62xm-2p83 | Moodle vulnerable to site administration SQL injection via XMLDB editor |
Solution
No solution given by the vendor.
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Thu, 07 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Moodle
Moodle moodle |
|
| Weaknesses | CWE-89 | |
| CPEs | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Moodle
Moodle moodle |
|
| Metrics |
ssvc
|
Thu, 07 Nov 2024 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SQL injection risk flaw was found in the XMLDB editor tool available to site administrators. | |
| Title | Moodle: site administration sql injection via xmldb editor | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2024-11-07T15:57:00.698Z
Reserved: 2024-08-13T07:15:00.598Z
Link: CVE-2024-43436
Updated: 2024-11-07T14:42:32.997Z
Status : Analyzed
Published: 2024-11-07T14:15:16.247
Modified: 2025-08-05T18:34:51.933
Link: CVE-2024-43436
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA