Moodle
  1. Moodle
  2. MDL-24081

multiple SQL injections in completion subsystem

    Details

    • Type: Bug Bug
    • Status: Closed
    • Priority: Blocker Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Course completion
    • Labels:
      None
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE
    • Rank:
      27222

      Description

      Whoever wrote that code did not understand the new DML api.

      1/ We MUST use bound params for all LIKE searches and all other parameters.
      2/ when you pass around $sql fragments you need to take the $params along with it

      The solution is to fix the completion api to accept $where+$params, not only $where. Somebody has to audit all DML related code there...

        Activity

        Hide
        Petr Škoda added a comment -

        I have found sql injections in:
        course/report/completion/*
        course/report/progress/*
        lib/completionlib.php

        At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike().

        Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.

        Show
        Petr Škoda added a comment - I have found sql injections in: course/report/completion/* course/report/progress/* lib/completionlib.php At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike(). Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.
        Hide
        Petr Škoda added a comment -

        Thank you!

        Show
        Petr Škoda added a comment - Thank you!
        Hide
        Aaron Barnes added a comment -

        No problem mate

        Show
        Aaron Barnes added a comment - No problem mate

          People

          • Votes:
            0 Vote for this issue
            Watchers:
            0 Start watching this issue

            Dates

            • Created:
              Updated:
              Resolved: