CVE-2021-32474: SQL Injection
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-32474?
CVE-2021-32474 is rated as a high severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2021-32474?
To fix CVE-2021-32474, update Moodle to version 3.10.4, 3.9.7, 3.8.9, or 3.5.18 or higher.
What versions of Moodle are affected by CVE-2021-32474?
CVE-2021-32474 affects Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions.
What are the exploit capabilities for CVE-2021-32474?
CVE-2021-32474 can be exploited through an XML-RPC call when MNet is enabled and requires site administrator access.
What is the impact of CVE-2021-32474 on Moodle installations?
The impact of CVE-2021-32474 includes potential unauthorized access to the database due to SQL injection vulnerabilities.