Uploaded image for project: 'Moodle'
  1. Moodle
  2. MDL-24081

multiple SQL injections in completion subsystem

    Details

    • Type: Bug
    • Status: Closed
    • Priority: Blocker
    • Resolution: Fixed
    • Affects Version/s: 2.0
    • Fix Version/s: 2.0
    • Component/s: Course completion
    • Labels:
      None
    • Affected Branches:
      MOODLE_20_STABLE
    • Fixed Branches:
      MOODLE_20_STABLE

      Description

      Whoever wrote that code did not understand the new DML api.

      1/ We MUST use bound params for all LIKE searches and all other parameters.
      2/ when you pass around $sql fragments you need to take the $params along with it

      The solution is to fix the completion api to accept $where+$params, not only $where. Somebody has to audit all DML related code there...

        Gliffy Diagrams

          Activity

          Hide
          skodak Petr Skoda added a comment -

          I have found sql injections in:
          course/report/completion/*
          course/report/progress/*
          lib/completionlib.php

          At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike().

          Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.

          Show
          skodak Petr Skoda added a comment - I have found sql injections in: course/report/completion/* course/report/progress/* lib/completionlib.php At the same time the code should be migrated to use new $DB->sql_like() instead of deprecated $DB->sql_ilike(). Ahh, it got assigned to Aaron, please let me know if you need any help with this, we need to fix this ASAP.
          Hide
          skodak Petr Skoda added a comment -

          Thank you!

          Show
          skodak Petr Skoda added a comment - Thank you!
          Hide
          sry_not4sale Aaron Barnes added a comment -

          No problem mate

          Show
          sry_not4sale Aaron Barnes added a comment - No problem mate

            People

            • Votes:
              0 Vote for this issue
              Watchers:
              0 Start watching this issue

              Dates

              • Created:
                Updated:
                Resolved:
                Fix Release Date:
                24/Nov/10