CVE-2025-63564
9.8 CRITICALPublished 2026-09-23 · Updated 2026-09-24
AI risk analysis
- Summary
- This vulnerability allows an attacker to execute arbitrary code via SQL injection in the Moodle Socialwall plugin versions 3.0 to 3.3, posing a critical risk.
- Exploitability
- Exploitation is relatively straightforward requiring crafted HTTP requests to the affected plugin version.
- Blast radius
- If exploited, this could result in complete compromise of the affected Moodle instance, leading to data loss and potential system takeover.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Moodle Socialwall plugin version 3.4 or later.
rcesql-injectionwebmoodle
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbitrary code via crafted HTTP requests
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-89
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- CRITICALCVE-2023-54399
- CRITICALCVE-2023-54400PoC
- MEDIUMCVE-2026-15941
- HIGHCVE-2026-18854
- CRITICALCVE-2026-62262PoC
- HIGHCVE-2026-70369
- HIGHCVE-2026-70370
- HIGHCVE-2026-70371
Related by shared AI tags and CWE weakness class. Browse the full archive.