AUGUST 5, 2026
Live Feed
Back to database
Case File

CVE-2013-4313

HIGH · CVSS 7.5 EPSS 1.21%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2013-09-16 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. It affects Microsoft. It may be remotely exploitable. It involves a SQL injection risk.

CVE
CVE-2013-4313
Severity
HIGH
CVSS
7.5
EPSS
1.21%
Microsoft

Original NVD Description

Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, and 2.5.x before 2.5.2 does not prevent use of '\0' characters in query strings, which might allow remote attackers to conduct SQL injection attacks against Microsoft SQL Server via a crafted string.