CVE-2021-20185: Medium severity moodle vulnerability
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that messaging did not impose a character limit when sending messages, which could result in client-side (browser) denial of service for users receiving very large messages.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20185?
CVE-2021-20185 has been classified as having a medium severity due to the potential for client-side denial of service.
How do I fix CVE-2021-20185?
To remediate CVE-2021-20185, upgrade to Moodle version 3.10.1, 3.9.4, 3.8.7, or 3.5.16.
Which versions of Moodle are affected by CVE-2021-20185?
Moodle versions prior to 3.10.1, 3.9.4, 3.8.7, and 3.5.16 are vulnerable to CVE-2021-20185.
What type of attack is associated with CVE-2021-20185?
CVE-2021-20185 could lead to a client-side denial of service attack by allowing the sending of excessively large messages.
Is user data compromised by CVE-2021-20185?
CVE-2021-20185 does not compromise user data, but it can disrupt service for users receiving large messages.