VULNERABILITY INTELLIGENCE

CVE-2012-3395

CVSS score6.5 MEDIUM
EPSS probability1.58%
CISA KEVNot currently listed
Published2012-07-23
Last modified2026-06-16
CVSS vectorAV:N/AC:L/Au:S/C:P/I:P/A:P

Description

SQL injection vulnerability in mod/feedback/complete.php in Moodle 2.0.x before 2.0.10, 2.1.x before 2.1.7, and 2.2.x before 2.2.4 allows remote authenticated users to execute arbitrary SQL commands via crafted form data.

Weakness classification

  • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Primary references