Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-24081

multiple SQL injections in completion subsystem

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Course completion
    • Labels:
      None
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE

      Description

      Whoever wrote that code did not understand the new DML api.

      1/ We MUST use bound params for all LIKE searches and all other parameters.
      2/ when you pass around $sql fragments you need to take the $params along with it

      The solution is to fix the completion api to accept $where+$params, not only $where. Somebody has to audit all DML related code there...

        Attachments

          Activity

            People

            • Assignee:
              sry_not4sale Aaron Barnes
              Reporter:
              skodak Petr Skoda
              Tester:
              Nobody
              Participants:
              Component watchers:
              Amaia Anabitarte, Carlos Escobedo, Sara Arjona (@sarjona), Víctor Déniz Falcón
            • Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Fix Release Date:
                24/Nov/10