Impact
A flaw in Moodle allows an authenticated user who can access the question bank web service to submit unsanitized input directly into database queries. This enables a classic SQL injection that may let the attacker view, modify, or delete data stored in the database, violating confidentiality and integrity.
Affected Systems
The vulnerability affects all installations of Moodle that expose the question bank web service to authenticated users. No specific version information is listed, so any Moodle deployment with this service active is potentially impacted until an update is applied.
Risk and Exploitability
The CVSS score of 5.5 reflects a moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, indicating a lower current exploitation likelihood. Because the attacker must first authenticate and obtain access to the question bank web service, the likely attack vector is a web‑based attack from within the organization or from an external attacker who has compromised user credentials. If the conditions are met, the exploit could compromise sensitive data but does not allow arbitrary code execution.
OpenCVE Enrichment