← Back to search

CVE-2025-63564

9.8 CRITICAL

Published 2026-09-23 · Updated 2026-09-24

AI risk analysis

Summary
This vulnerability allows an attacker to execute arbitrary code via SQL injection in the Moodle Socialwall plugin versions 3.0 to 3.3, posing a critical risk.
Exploitability
Exploitation is relatively straightforward requiring crafted HTTP requests to the affected plugin version.
Blast radius
If exploited, this could result in complete compromise of the affected Moodle instance, leading to data loss and potential system takeover.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to Moodle Socialwall plugin version 3.4 or later.
rcesql-injectionwebmoodle

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-89

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.