The vulnerability was found Moodle which exists due to insufficient sanitization of user-supplied data in external Wiki method for listing pages. A remote attacker can send a specially crafted request to the affected application and execute limited SQL commands within the application database.
{ "github_reviewed_at": "2023-05-02T23:13:30Z", "cwe_ids": [ "CWE-89" ], "nvd_published_at": "2023-05-02T20:15:11Z", "severity": "HIGH", "github_reviewed": true }