Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-24081

multiple SQL injections in completion subsystem

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Course completion
    • Labels:
      None
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE

      Description

      Whoever wrote that code did not understand the new DML api.

      1/ We MUST use bound params for all LIKE searches and all other parameters.
      2/ when you pass around $sql fragments you need to take the $params along with it

      The solution is to fix the completion api to accept $where+$params, not only $where. Somebody has to audit all DML related code there...

        Gliffy Diagrams

          Attachments

            Activity

            Hide
            skodak Petr Skoda added a comment -

            I have found sql injections in:
            course/report/completion/*
            course/report/progress/*
            lib/completionlib.php

            At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike().

            Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.

            Show
            skodak Petr Skoda added a comment - I have found sql injections in: course/report/completion/* course/report/progress/* lib/completionlib.php At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike(). Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.
            Hide
            skodak Petr Skoda added a comment -

            Thank you!

            Show
            skodak Petr Skoda added a comment - Thank you!
            Hide
            sry_not4sale Aaron Barnes added a comment -

            No problem mate

            Show
            sry_not4sale Aaron Barnes added a comment - No problem mate

              People

              • Votes:
                0 Vote for this issue
                Watchers:
                0 Start watching this issue

                Dates

                • Created:
                  Updated:
                  Resolved:
                  Fix Release Date:
                  24/Nov/10