Moodle SQL Injection Vulnerability in Course Search Module List Filter

Vulnerability

A SQL injection vulnerability has been identified in the course search module, specifically within the module list filter. This issue affects Moodle versions 4.5 prior to 4.5.1, 4.4 prior to 4.4.5, 4.3 prior to 4.3.9, 4.1 prior to 4.1.15, and earlier unsupported versions.

Impact

Exploitation of this vulnerability allows for SQL injection, which could lead to unauthorized data access or manipulation within the application's database.

Remediation

Users can upgrade to Moodle versions 4.5.2, 4.4.6, 4.3.10, or 4.1.16 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.0
impact
5.0
exploitability
8.1
remediation
7.7
relevance
0.0
threat
3.2
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.