Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-24081

multiple SQL injections in completion subsystem

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Course completion
    • Labels:
      None
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE

      Description

      Whoever wrote that code did not understand the new DML api.

      1/ We MUST use bound params for all LIKE searches and all other parameters.
      2/ when you pass around $sql fragments you need to take the $params along with it

      The solution is to fix the completion api to accept $where+$params, not only $where. Somebody has to audit all DML related code there...

        Gliffy Diagrams

          Attachments

            Activity

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                0 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Fix Release Date:
                  24/Nov/10