Description
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
Published: 2026-09-30
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL injection in Moodle question bank web service
Action: Patch
AI Analysis

Impact

A flaw in Moodle allows an authenticated user who can access the question bank web service to submit unsanitized input directly into database queries. This enables a classic SQL injection that may let the attacker view, modify, or delete data stored in the database, violating confidentiality and integrity.

Affected Systems

The vulnerability affects all installations of Moodle that expose the question bank web service to authenticated users. No specific version information is listed, so any Moodle deployment with this service active is potentially impacted until an update is applied.

Risk and Exploitability

The CVSS score of 5.5 reflects a moderate severity. EPSS is not available and the issue is not listed in the CISA KEV catalog, indicating a lower current exploitation likelihood. Because the attacker must first authenticate and obtain access to the question bank web service, the likely attack vector is a web‑based attack from within the organization or from an external attacker who has compromised user credentials. If the conditions are met, the exploit could compromise sensitive data but does not allow arbitrary code execution.

Generated by OpenCVE AI on September 30, 2026 at 11:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Moodle release that addresses the question bank web service SQL injection flaw.
  • Restrict the question bank web service to only the users who require it by configuring Moodle roles and capabilities.
  • Limit the Moodle database user permissions for the question bank service to read‑only or the minimum required scope and monitor for abnormal query patterns.

Generated by OpenCVE AI on September 30, 2026 at 11:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Moodle
Moodle moodle
Vendors & Products Moodle
Moodle moodle

Wed, 30 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
Title Moodle: sql injection in question bank web service
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-09-30T08:36:01.859Z

Reserved: 2026-09-29T14:03:38.493Z

Link: CVE-2026-102578

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-30T09:17:14.810

Modified: 2026-09-30T09:17:14.810

Link: CVE-2026-102578

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T13:00:14Z

Weaknesses
  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')