MDL-84271 core_course: Validate module list in search

* We need to validate the list of modules in the course search

Co-authored-by: Lars Bonczek <[email protected]>
This commit is contained in:
Laurent David
2025-02-06 11:18:52 +08:00
committed by Jun Pataleta
co-authored by Lars Bonczek
parent acaabbd33a
commit 44971ebf69
+7 -2
View File
@@ -1645,8 +1645,13 @@ class core_course_category implements renderable, cacheable_object, IteratorAggr
$params = array('blockname' => $blockname);
} else if (!empty($search['modulelist'])) {
// Search courses that have module with specified name.
$where = "c.id IN (SELECT DISTINCT module.course ".
"FROM {".$search['modulelist']."} module)";
if (array_key_exists($search['modulelist'], core_component::get_plugin_list('mod'))) {
// If module plugin exists, use module name as table name.
$where = "c.id IN (SELECT DISTINCT module.course FROM {{$search['modulelist']}} module)";
} else {
// Otherwise, return empty list of courses.
$where = '1=0';
}
$params = array();
} else if (!empty($search['tagid'])) {
// Search courses that are tagged with the specified tag.