Loading HuntDB...

CVE-2021-32478

UNKNOWN
Published 2022-03-11T00:00:00
Actions:

Expert Analysis

Professional remediation guidance

Get tailored security recommendations from our analyst team for CVE-2021-32478. We'll provide specific mitigation strategies based on your environment and risk profile.

No CVSS data available

Description

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

Available Exploits

Moodle - Cross-Site Scripting

Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, and earlier unsupported versions contain a cross-site scripting vulnerability via the redirect_uri parameter.

ID: moodle-xss
Author: hackergautam Medium

Related News

No news articles found for this CVE.

GitHub Security Advisories

Community-driven vulnerability intelligence from GitHub

✓ GitHub Reviewed MODERATE

Moodle reflected XSS

GHSA-78fm-qhh8-8858

Advisory Details

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

Affected Packages

Packagist moodle/moodle
ECOSYSTEM: ≥3.10 <3.10.4
Packagist moodle/moodle
ECOSYSTEM: ≥3.9 <3.9.7
Packagist moodle/moodle
ECOSYSTEM: ≥3.8 <3.8.9

CVSS Scoring

CVSS Score

5.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Advisory provided by GitHub Security Advisory Database. Published: March 12, 2022, Modified: July 12, 2023

References

Published: 2022-03-11T00:00:00
Last Modified: 2024-08-03T23:17:29.546Z
Copied to clipboard!