CVE-2026-102578: Moodle: sql injection in question bank web service
A flaw was found in Moodle. A SQL injection risk was identified in a question bank web service, allowing unsanitized input to reach a database query. The advisory does not state the exact capability required to call the affected web service function; this draft assumes it requires an elevated (teacher-level) role rather than being reachable by a basic authenticated user.
Other sources
A flaw was found in Moodle. An authenticated attacker with access to the question bank web service can submit unsanitized input directly into database queries, resulting in a SQL (Structured Query Language) injection vulnerability. This issue could allow an attacker to view, alter, or delete sensitive data stored in the underlying database.
— MITRE
Affected Software
Event History
Frequently Asked Questions
Which deployments should be prioritized for review?
Prioritize Moodle deployments where authenticated users can access the question bank web service. The advisory does not state the exact capability needed to invoke the affected function; the draft assumes a teacher-level or similarly elevated role.
Can an unauthenticated or basic authenticated user exploit this issue?
The available information describes an authenticated attacker with access to the question bank web service. It does not establish that unauthenticated users or basic authenticated users can reach the vulnerable function.
Are affected versions, fixed versions, or detection indicators available?
No affected or fixed version information is provided. The advisory also provides no specific logs, database indicators, or other detection guidance for identifying prior exploitation.