A flaw was found in moodle where an SQL injection risk was identified in Badges code relating to configuring criteria.