First published: Fri Mar 11 2022(Updated: )
Teachers exporting a forum in CSV format could receive a CSV of forums from all courses in some circumstances. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6 and 3.8 to 3.8.8 are affected.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.10.0<3.10.4 | 3.10.4 |
composer/moodle/moodle | >=3.9.0<3.9.7 | 3.9.7 |
composer/moodle/moodle | >=3.8.0<3.8.9 | 3.8.9 |
Moodle | >=3.8.0<3.8.9 | |
Moodle | >=3.9.0<3.9.7 | |
Moodle | >=3.10.0<3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32472 is classified as a medium severity vulnerability.
To fix CVE-2021-32472, upgrade to Moodle version 3.10.4, 3.9.7, or 3.8.9.
CVE-2021-32472 affects teachers using Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, and 3.8 to 3.8.8.
CVE-2021-32472 can cause unintended exposure of forum data across all courses when exporting to CSV.
There is no confirmed workaround for CVE-2021-32472; updating to the fixed versions is the recommended approach.