SQL Injection Vulnerability in Moodle by Moodle
CVE-2026-102578

5.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
30 September 2026

What is CVE-2026-102578?

A vulnerability in Moodle allows authenticated attackers with access to the question bank web service to execute unsanitized input directly into database queries. This SQL injection flaw can enable malicious users to view, modify, or even delete sensitive data stored within the database, posing a significant risk to the integrity and confidentiality of user information.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Upstream acknowledges Caveeroo as the original reporter.
.