Loading...
Loading...
Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.
September 16, 2013
April 29, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2013-4313
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.