{"id":"CVE-2025-63564","published":"2026-09-23T17:17:14.323","lastModified":"2026-09-24T21:08:55.030","description":"SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests","cvssScore":9.8,"cvssSeverity":"CRITICAL","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-89"],"vendors":[],"products":[],"references":[{"url":"http://moodle.com","tags":[]},{"url":"https://medium.com/@lcrawfqrd/sqli-in-moodle-plugin-9f0ce4eb05f2","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows an attacker to execute arbitrary code via SQL injection in the Moodle Socialwall plugin versions 3.0 to 3.3, posing a critical risk.","exploitability":"Exploitation is relatively straightforward requiring crafted HTTP requests to the affected plugin version.","blast_radius":"If exploited, this could result in complete compromise of the affected Moodle instance, leading to data loss and potential system takeover.","remediation":"Upgrade to Moodle Socialwall plugin version 3.4 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","sql-injection","web","moodle"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-27T08:51:08.503Z"}}