Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:moodle:moodle:-:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
ssvc
|
Status: PUBLISHED
Assigner: fedora
Published: 2023-03-23T00:00:00.000Z
Updated: 2024-08-02T12:38:24.625Z
Reserved: 2023-03-14T00:00:00.000Z
Link: CVE-2023-28329
Updated: 2024-08-02T12:38:24.625Z
Status : Modified
Published: 2023-03-23T21:15:19.857
Modified: 2024-11-21T07:54:51.337
Link: CVE-2023-28329
No data.