MSA-09-0012: SQL injections when importing outcomes

MSA-09-0012: SQL injections when importing outcomes

by Petr Skoda -
Number of replies: 0
Topic: SQL injections when importing outcomes
Severity: Major
Versions affected: < 1.9.5
Reported by: internal review
Issue no.: MDL-19036
Solution: upgrade to 1.9.5


Description:
When reviewing the import outcomes code, it was discovered that incorrect coding allowed SQL injections. By default only trusted users are allowed to use this part of gradebook. It can not be exploited by students.