CVE-2021-20279: XSS
Published Mar 15, 2021
·Updated
The ID number user profile field required additional sanitizing to prevent a stored XSS risk in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Other sources
The ID number user profile field required additional sanitizing to prevent a stored XSS risk.
References:
https://moodle.org/mod/forum/discuss.php?d=419650
— Red Hat
Affected Software
10 affected componentsFixes available
redhat/moodle<3.10.2
3.10.2
redhat/moodle<3.9.5
3.9.5
redhat/moodle<3.8.8
3.8.8
redhat/moodle<3.5.17
3.5.17
Moodle moodle>=3.5.0<3.5.17
Moodle moodle>=3.8.0<3.8.8
Moodle moodle>=3.9.0<3.9.5
Moodle moodle>=3.10.0<3.10.2
Fedoraproject Fedora=32
Fedoraproject Fedora=34
Remediation
Patch Available
Event History
Mar 15, 2021
CVE Published
via MITRE·09:35 PM
Data Sourced
via MITRE·09:35 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-20279?
CVE-2021-20279 has been classified as a medium severity vulnerability due to the stored XSS risk it poses.
2
How do I fix CVE-2021-20279?
To fix CVE-2021-20279, upgrade to Moodle versions 3.10.2, 3.9.5, 3.8.8, or 3.5.17 or later.
3
What type of vulnerability is CVE-2021-20279?
CVE-2021-20279 is a stored Cross-Site Scripting (XSS) vulnerability.
4
Which versions of Moodle are affected by CVE-2021-20279?
CVE-2021-20279 affects Moodle versions prior to 3.10.2, 3.9.5, 3.8.8, and 3.5.17.
5
Can CVE-2021-20279 be exploited remotely?
Yes, CVE-2021-20279 can be exploited remotely due to its nature as a stored XSS vulnerability.