Sceawere

Vulnerability Detail

CVE-2026-102578UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Moodle Question Bank SQL Injection

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.5
Creation Date
3h ago
Vendor
—
Product
N/A
Attack Type
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.5",
  "pubDate": "2026-09-30T09:17:14.810Z",
  "pubdate": "2026-09-30T09:17:14.810Z",
  "executiveSummary": "This vulnerability is an SQL injection flaw identified within the Moodle question bank web service. The vulnerability stems from the improper sanitization of user-supplied input before it is incorporated into database queries.\nAn authenticated attacker possessing access to the question bank service can exploit this weakness to execute arbitrary SQL commands against the backend database. This capability facilitates unauthorized data retrieval, modification, or deletion, posing a significant risk to the integrity, confidentiality, and availability of the Moodle platform's data.\nThe attack requires successful authentication to the Moodle environment, specifically utilizing the interface associated with the question bank functionality. Given the potential for full database compromise, the impact is rated as critical, necessitating immediate remediation efforts to prevent unauthorized access to sensitive institutional or user data.",
  "technicalDetails": "The root cause of this vulnerability is the failure of the Moodle question bank web service to properly sanitize or parameterize user-supplied input before passing it to the database query execution engine. By failing to enforce strict input validation or utilize prepared statements, the application creates a condition where malicious SQL payloads can be injected directly into active database queries.\nThe attack flow begins with an attacker authenticating to the Moodle platform. Upon gaining access to the question bank web service, the attacker identifies entry points where user-controlled parameters are processed by the backend. By submitting a crafted request containing SQL control characters (e.g., single quotes, comment indicators, or stacked query operators), the attacker can break out of the intended query structure.\nOnce the query logic is subverted, the underlying database driver executes the injected instructions alongside the legitimate query. This allows the attacker to manipulate the query's behavior, such as using UNION-based techniques to extract data from unauthorized tables or executing UPDATE/DELETE statements to alter or destroy information.\nThe vulnerability is exposed through the web service interface and does not require complex network positioning, provided the attacker has valid credentials. The exposure is directly tied to the interaction between the Moodle application logic and the SQL database. Post-exploitation impact is severe, as the attacker effectively operates with the permissions of the database user account configured for Moodle, potentially leading to full administrative compromise of the database server and sensitive institutional data hosted within.\nThis SQL injection vulnerability represents a failure in secure coding practices within the question bank component, specifically regarding the handling of dynamic query construction. The lack of parameterized queries or adequate input filtering allows for the execution of arbitrary commands, enabling an attacker to bypass standard application-level access controls entirely."
}
CVE-2026-102578: Moodle Question Bank SQL Injection (MEDIUM Severity, CVSS: 5.5) | Sceawere