Description
An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
Remediation
References
Related Vulnerabilities
Oracle Application Server CVE-2007-0280 Vulnerability (CVE-2007-0280)
SharePoint CVE-2021-43876 Vulnerability (CVE-2021-43876)
Squid Improper Input Validation Vulnerability (CVE-2021-33620)
WordPress Plugin ActiveCampaign-Forms, Site Tracking, Live Chat Cross-Site Request Forgery (8.0.1)
WordPress Plugin SEO Redirection-301 Redirect Manager Cross-Site Scripting (4.2)