Since long before the pandemic, teleeducation platforms have proliferated. The one that stands out the most in terms of use is Moodle, Open Source. This platform is used by a multitude of institutions and companies.

The latest vulnerability discovered is located in a function that allows the creation of medals to be awarded to students and could leak sensitive information from the database.

This vulnerability can be exploited using second-order SQL injections, in which malicious SQL queries are stored. Fortunately, This vulnerability is complex to exploit as you need to be registered with a teacher role to access the vulnerable component.

To date, the Moodle development team has not been notified by the usual notification channels, So so far the vulnerability has not been fixed.

Fountain: Segu-Info

Image: Pixabay


Leave a Reply

Your email address will not be published. Required fields are marked *

More news
A cybercriminal manages to use AI to steal data from the Mexican Government
Read more »
Intec creates an AI that redefines the rules of the game in cybersecurity in the AI era.
Read more »
Una exfiltración de datos afecta a un proveedor de Adidas
Read more »
Se incrementan un 26% los incidentes de ciberseguridad
Read more »
Un ciberataque paraliza en Roma la Universidad La Sapienza
Read more »