SQL Injection Vulnerability in Moodle by Moodle
CVE-2026-102578
5.5MEDIUM
What is CVE-2026-102578?
A vulnerability in Moodle allows authenticated attackers with access to the question bank web service to execute unsanitized input directly into database queries. This SQL injection flaw can enable malicious users to view, modify, or even delete sensitive data stored within the database, posing a significant risk to the integrity and confidentiality of user information.
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Upstream acknowledges Caveeroo as the original reporter.
