CVE-2021-20282: Medium severity moodle vulnerability
When creating a user account, it was possible to verify the account without having access to the verification email link/secret in moodle before 3.10.2, 3.9.5, 3.8.8, 3.5.17.
Other sources
When creating a user account, it was possible to verify the account without having access to the verification email link/secret.
References:
https://moodle.org/mod/forum/discuss.php?d=419653
— Red Hat
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-20282?
CVE-2021-20282 is considered a medium severity vulnerability due to its impact on user account security.
How do I fix CVE-2021-20282?
To fix CVE-2021-20282, update Moodle to version 3.10.2, 3.9.5, 3.8.8, or 3.5.17.
Which versions of Moodle are affected by CVE-2021-20282?
CVE-2021-20282 affects Moodle versions prior to 3.10.2, 3.9.5, 3.8.8, and 3.5.17.
How can CVE-2021-20282 be exploited?
CVE-2021-20282 can be exploited by creating a user account without needing access to the verification email link.
What are the potential consequences of CVE-2021-20282?
The potential consequences of CVE-2021-20282 include unauthorized account access and implications for user data security.