CVE-2021-20184: Medium severity moodle vulnerability
Published Jan 28, 2021
·Updated
It was found in Moodle before version 3.10.1, 3.9.4 and 3.8.7 that a insufficient capability checks in some grade related web services meant students were able to view other students grades.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.10<3.10.1
3.10.1
composer/moodle/moodle>=3.9<3.9.4
3.9.4
composer/moodle/moodle>=3.8<3.8.7
3.8.7
Moodle moodle<3.8.7
Moodle moodle>=3.9.0<3.9.4
Moodle moodle>=3.10.0<3.10.1
Remediation
Patch Available
Event History
Jan 28, 2021
CVE Published
via MITRE·06:44 PM
Data Sourced
via MITRE·06:44 PM
DescriptionWeakness
May 24, 2022
Advisory Published
via GitHub·05:40 PM
Frequently Asked Questions
1
What is the severity of CVE-2021-20184?
CVE-2021-20184 is classified as a medium severity vulnerability due to insufficient capability checks allowing students to view other students' grades.
2
How do I fix CVE-2021-20184?
To fix CVE-2021-20184, upgrade Moodle to version 3.10.1, 3.9.4, or 3.8.7.
3
Which versions of Moodle are affected by CVE-2021-20184?
CVE-2021-20184 affects Moodle versions before 3.10.1, 3.9.4, and 3.8.7.
4
What types of attacks can CVE-2021-20184 enable?
CVE-2021-20184 can enable unauthorized access to sensitive student grade information.
5
Is there a workaround for CVE-2021-20184?
There is no documented workaround for CVE-2021-20184; upgrading to a fixed version is the recommended course of action.