External risk intelligence

Moodle Socialwall Plugin SQL Injection Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-63564

The vulnerability exists in a Moodle plugin. Moodle is a web-based learning management system typically deployed as an internet-facing web application. Since the vulnerable component functions within a web service that is commonly exposed to the internet to facilitate remote access for users, the attack surface is considered likely to be reachable.

SQL Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A SQL injection vulnerability has been identified in a Moodle Socialwall plugin, potentially allowing unauthorized code execution through crafted web requests. This issue affects specific versions of the plugin and is characterized by its critical severity and network-accessible attack vector, indicating a broad potential exposure.

  • A plugin flaw can let attackers run their own code.
  • It impacts Moodle, a widely used learning platform.
  • Confirm if our Moodle Socialwall plugin is affected.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending specially crafted HTTP requests to a Moodle instance running the Socialwall plugin. Because the plugin is internet-facing and requires no authentication to access, an attacker can directly interact with the vulnerable code. This SQL injection vulnerability could lead to unauthorized code execution on the affected server.

  • No authentication needed.
  • Crafted HTTP requests trigger SQL injection.
  • Arbitrary code execution risk.

Live Threat

Current exploitation, exposure, and threat context

A SQL injection vulnerability in the Moodle Socialwall plugin could allow an unauthenticated attacker to execute arbitrary code by sending specially crafted HTTP requests. This could lead to the compromise of the Moodle instance.

  • Moodle Socialwall plugin data and code.
  • Via crafted HTTP requests.
  • Arbitrary code execution.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Moodle Socialwall plugin vulnerability requires action from teams responsible for Moodle instances, likely the platform or infrastructure teams, in coordination with application owners who manage plugin deployments. The first practical step is to identify all Moodle instances, assess the exposure and business criticality of any using the affected Socialwall plugin versions, and confirm the accountable owner for remediation planning.

  • Platform or application owners should address.
  • Verify Socialwall plugin usage and reachability.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Moodle Socialwall plugin?

Moodle is a popular open-source learning management system used by schools and organizations to create online courses. The Socialwall plugin is an add-on component for Moodle that enhances community interaction by providing a social-media-style interface where students and teachers can post updates, share resources, and comment on activities within the learning environment.

What does SQL injection mean for CVE-2025-63564?

This vulnerability is classified as CWE-89, or Improper Neutralization of Special Elements used in an SQL Command. It means the plugin fails to properly filter input from users before including it in database queries. An attacker can supply malicious SQL code through a web request, tricking the database into executing unauthorized commands that could compromise the entire server.

How is this vulnerability triggered?

An attacker triggers this flaw by sending a specially crafted HTTP request directly to a server running the affected plugin. No special user privileges or prior login sessions are required to initiate the attack. However, the flaw is only present if the specific vulnerable versions of the Socialwall plugin are installed; simply having Moodle installed without this specific plugin does not trigger the bug.

Is my Moodle instance at risk?

According to Halo Surface Signal, Moodle is frequently deployed as an internet-facing application to support remote access for students and staff, which makes it highly reachable. If your installation is accessible via the public internet and uses the Socialwall plugin, it faces a higher likelihood of being targeted compared to internal-only systems, as the attack path does not require authentication.

How should I respond to this vulnerability?

First, conduct an inventory to identify all Moodle instances in your environment and determine if any are running the Socialwall plugin versions 3.0 through 3.3. Once identified, document which systems are internet-facing to prioritize them, and engage the appropriate application owners or system administrators to coordinate a review of the plugin configuration and assess the need for updates or removal.

References