MSA-09-0012: SQL injections when importing outcomes

MSA-09-0012: SQL injections when importing outcomes

Petr Skoda發表於
Number of replies: 0
Topic: SQL injections when importing outcomes
Severity: Major
Versions affected: < 1.9.5
Reported by: internal review
Issue no.: MDL-19036
Solution: upgrade to 1.9.5


Description:
When reviewing the import outcomes code, it was discovered that incorrect coding allowed SQL injections. By default only trusted users are allowed to use this part of gradebook. It can not be exploited by students.