Show plain JSON{"dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": {"state": "PUBLISHED", "cveId": "CVE-2023-35132", "assignerOrgId": "92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5", "assignerShortName": "fedora", "dateUpdated": "2024-08-02T16:23:59.341Z", "dateReserved": "2023-06-13T00:00:00", "datePublished": "2023-06-22T00:00:00"}, "containers": {"cna": {"title": "Moodle: minor sql injection risk on mnet sso access control page", "metrics": [{"other": {"content": {"value": "Low", "namespace": "https://access.redhat.com/security/updates/classification/"}, "type": "Red Hat severity rating"}}, {"cvssV3_1": {"attackComplexity": "LOW", "attackVector": "NETWORK", "availabilityImpact": "LOW", "baseScore": 6.3, "baseSeverity": "MEDIUM", "confidentialityImpact": "LOW", "integrityImpact": "LOW", "privilegesRequired": "LOW", "scope": "UNCHANGED", "userInteraction": "NONE", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L", "version": "3.1"}, "format": "CVSS"}], "descriptions": [{"lang": "en", "value": "A limited SQL injection risk was identified on the Mnet SSO access control page. This flaw affects Moodle versions 4.2, 4.1 to 4.1.3, 4.0 to 4.0.8, 3.11 to 3.11.14, 3.9 to 3.9.21 and earlier unsupported versions."}], "affected": [{"versions": [{"status": "affected", "version": "4.2.0", "lessThan": "4.2.1", "versionType": "semver"}, {"status": "affected", "version": "4.1.0", "lessThan": "4.1.4", "versionType": "semver"}, {"status": "affected", "version": "4.0.0", "lessThan": "4.0.9", "versionType": "semver"}, {"status": "affected", "version": "3.11.0", "lessThan": "3.11.15", "versionType": "semver"}, {"status": "affected", "version": "0", "lessThan": "3.9.22", "versionType": "semver"}], "packageName": "moodle", "collectionURL": "https://git.moodle.org", "defaultStatus": "unaffected"}], "references": [{"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214371", "name": "RHBZ#2214371", "tags": ["issue-tracking", "x_refsource_REDHAT"]}, {"name": "FEDORA-2023-3ca351353f", "tags": ["vendor-advisory"], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC/"}, {"name": "FEDORA-2023-ce24b63b36", "tags": ["vendor-advisory"], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT/"}, {"url": "https://moodle.org/mod/forum/discuss.php?d=447830"}], "datePublic": "2023-06-19T04:00:00+00:00", "problemTypes": [{"descriptions": [{"cweId": "CWE-89", "description": "Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "lang": "en", "type": "CWE"}]}], "x_redhatCweChain": "CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')", "timeline": [{"lang": "en", "time": "2023-06-12T00:00:00+00:00", "value": "Reported to Red Hat."}, {"lang": "en", "time": "2023-06-19T04:00:00+00:00", "value": "Made public."}], "providerMetadata": {"orgId": "92fb86c3-55a5-4fb5-9c3f-4757b9e96dc5", "shortName": "fedora", "dateUpdated": "2024-04-19T13:40:32.565Z"}}, "adp": [{"title": "CISA ADP Vulnrichment", "metrics": [{"other": {"type": "ssvc", "content": {"id": "CVE-2023-35132", "role": "CISA Coordinator", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "partial"}], "version": "2.0.3", "timestamp": "2024-04-19T20:53:51.486692Z"}}}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-06-04T17:18:36.845Z"}}, {"providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-02T16:23:59.341Z"}, "title": "CVE Program Container", "references": [{"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2214371", "name": "RHBZ#2214371", "tags": ["issue-tracking", "x_refsource_REDHAT", "x_transferred"]}, {"name": "FEDORA-2023-3ca351353f", "tags": ["vendor-advisory", "x_transferred"], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7A72KX4WU6GK2CX4TKYFGFASPKOEOJFC/"}, {"name": "FEDORA-2023-ce24b63b36", "tags": ["vendor-advisory", "x_transferred"], "url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/I5QAEAGJ44NVXLAJFJXKARKC45OGEDXT/"}, {"url": "https://moodle.org/mod/forum/discuss.php?d=447830", "tags": ["x_transferred"]}]}]}}