Picture of Petr Škoda (skodak)
MSA-09-0012: SQL injections when importing outcomes
by Petr Škoda (skodak) - Wednesday, May 20, 2009, 07:01 PM
 
Topic: SQL injections when importing outcomes
Severity: Major
Versions affected: < 1.9.5
Reported by: internal review
Issue no.: MDL-19036
Solution: upgrade to 1.9.5


Description:
When reviewing the import outcomes code, it was discovered that incorrect coding allowed SQL injections. By default only trusted users are allowed to use this part of gradebook. It can not be exploited by students.