Description
** DISPUTED ** Moodle 3.1.2 allows remote attackers to obtain sensitive information via unspecified vectors, related to a "SQL Injection" issue affecting the Administration panel function in the installation process component. NOTE: the vendor disputes the relevance of this report, noting that "the person who is installing Moodle must know database access credentials and they can access the database directly; there is no need for them to create a SQL injection in one of the installation dialogue fields."
Remediation
References
Related Vulnerabilities
WordPress Plugin Soundy Audio Playlist Cross-Site Scripting (4.6)
Oracle Database Server CVE-2006-5337 Vulnerability (CVE-2006-5337)
Drupal Core 8.9.x Security Bypass (8.9.0 - 8.9.5)
WordPress Plugin Roomcloud Multiple Cross-Site Scripting Vulnerabilities (1.1)
WordPress 4.2.x Cross-Site Scripting Vulnerability (4.2 - 4.2.5)