An SQL injection risk was identified in Badges code relating to configuring criteria. Access to the relevant capability was limited to teachers and managers by default.
{
"nvd_published_at": "2022-03-25T19:15:00Z",
"cwe_ids": [
"CWE-89"
],
"severity": "HIGH",
"github_reviewed_at": "2022-04-01T18:03:23Z",
"github_reviewed": true
}