CVE-2023-28329: Moodle

High severity, CVSS 8.8. EPSS: 1.2% chance of exploitation in the next 30 days.

Insufficient validation of profile field availability condition resulted in an SQL injection risk (by default only available to teachers and managers).

Affected products

  • Moodle Moodle: after 3.9.0, before 3.9.20 (fixed in 3.9.20); after 3.11.0, before 3.11.13 (fixed in 3.11.13); after 4.0.0, before 4.0.7 (fixed in 4.0.7); version 3.9.0 only; version 3.11.0 only; version 4.0.0 only; …

Published 2023-03-23. Last modified 2026-06-17.