SQL injection vulnerability in calendar/event.php in the calendar implementation in Moodle 1.9.x before 1.9.18 allows remote authenticated users to execute arbitrary SQL commands via a crafted calendar event.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-07-20 20:38
Updated : 2020-12-01 06:43
NVD link : CVE-2012-2363
Mitre link : CVE-2012-2363
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
moodle
- moodle