Description
SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.
Remediation
References
Related Vulnerabilities
WordPress Plugin MSMC-Redirect After Comment Multiple Vulnerabilities (2.1.2)
WordPress Plugin WooCommerce Product Feed Manager Security Bypass (2.2.3)
WordPress Plugin Arigato Autoresponder and Newsletter Cross-Site Scripting (2.3.1)
Moodle Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2016-2156)
WordPress Plugin Import Social Events Cross-Site Scripting (1.6.6)