{"id":"CVE-2010-1615","aliases":[],"url":"https://o3.security/vulnerability/CVE-2010-1615","summary":"Moodle vulnerable to SQL injection","details":"Multiple SQL injection vulnerabilities in Moodle 1.8.x before 1.8.12 and 1.9.x before 1.9.8 allow remote attackers to execute arbitrary SQL commands via vectors related to (1) the add_to_log function in mod/wiki/view.php in the wiki module, or (2) \"data validation in some forms elements\" related to lib/form/selectgroups.php.","published":"2022-05-13T01:13:09Z","modified":"2025-04-12T01:42:07.036083Z","cvss":null,"epss":{"score":0.0172,"percentile":0.76101,"asOf":"2026-09-09"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"1.8.12"},{"ecosystem":"Packagist","name":"moodle/moodle","fixedVersion":"1.9.8"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2010-1615"},{"type":"PACKAGE","url":"https://github.com/moodle/moodle"},{"type":"WEB","url":"http://cvs.moodle.org/moodle/lib/form/selectgroups.php?r1=1.2.4.2&r2=1.2.4.3"},{"type":"WEB","url":"http://cvs.moodle.org/moodle/mod/wiki/view.php?r1=1.76.2.6&r2=1.76.2.7"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2010-05/msg00001.html"},{"type":"WEB","url":"http://moodle.org/security"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-04-12T01:42:07.036083Z"}}