← Back

CVE-2022-0983

nvd nist
Published: Mar 25, 2022Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.

Affected (6)

1 product
Moodle
2 products
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Moodle
From 3.10.0 to 3.10.10
From 3.11.0 to 3.11.6
From 3.9.0 to 3.9.13
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 35
Version 36
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 7.0

Timeline

No history available yet.