CVE-2025-26533: SQL injection risk in course search module list filter
An SQL injection risk was identified in the module list filter within course search.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.1.16 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.3.10 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.4.6 - Upgrade
Upgrade
composer/moodle/moodleto a version that resolves this vulnerability.Fixed in 4.5.2
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26533?
CVE-2025-26533 is classified as a high-severity vulnerability due to its potential for SQL injection attacks.
How do I fix CVE-2025-26533?
To fix CVE-2025-26533, upgrade to Moodle versions 4.1.16, 4.3.10, 4.4.6, or 4.5.2, depending on your current version.
What kind of attack can CVE-2025-26533 enable?
CVE-2025-26533 can enable attackers to perform SQL injection attacks, compromising the security of the underlying database.
Which software versions are affected by CVE-2025-26533?
CVE-2025-26533 affects Moodle versions prior to 4.1.16, 4.3.10, 4.4.6, and 4.5.2.
Where can I check for updates regarding CVE-2025-26533?
You can check for updates and discussions about CVE-2025-26533 on the official Moodle forums.