Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Message below arrived over the weekend from one of the sec mailing lists - no confirmation of it on the moodle site or other mailing list members yet though...

 

I don't have a moodle install to test the proof of concept on but thought a few people might want to be aware if they run their Moodle in the configuration mentioned below so they can keep an eye out for security updates.

 

Product:

moodle 1.6.2

http://www.moodle.org

 

Vulnerability:

SQL injection

 

Notes:

- SQL injection can be used to obtain password hash

- the moodle blog "module" must be enabled

- guest access to the blog must be enabled

 

Left the proof of concept code out, wasn't sure it would be welcome here 8O

Posted
I was looking physically at the moodle files. I presume the blog module would be hiding in "/mod/blog" which doesn't appear to exist in our install.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...