CVE-2021-21809: OS Command Injection
A command execution vulnerability exists in the default legacy spellchecker plugin in a few Moodle multiple specific versions. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
Other sources
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21809?
CVE-2021-21809 has been classified as a high-severity vulnerability due to its potential for command execution with administrator privileges.
How do I fix CVE-2021-21809?
To fix CVE-2021-21809, upgrade to a patched version of Moodle, such as 3.11.3 or later.
What versions of Moodle are affected by CVE-2021-21809?
CVE-2021-21809 affects Moodle versions 3.8.0, 3.10.0, and 3.11.2.
Can an attacker exploit CVE-2021-21809 without administrator privileges?
No, an attacker must have administrator privileges to exploit CVE-2021-21809.
What type of vulnerability is CVE-2021-21809?
CVE-2021-21809 is a command execution vulnerability that can be triggered by specially crafted HTTP requests.