First published: Fri Mar 11 2022(Updated: )
ID numbers displayed in the quiz grading report required additional sanitizing to prevent a stored XSS risk. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.10<3.10.4 | 3.10.4 |
composer/moodle/moodle | >=3.9<3.9.7 | 3.9.7 |
composer/moodle/moodle | >=3.8<3.8.9 | 3.8.9 |
composer/moodle/moodle | >=3.5<3.5.18 | 3.5.18 |
Moodle | <3.5.18 | |
Moodle | >=3.8.0<3.8.9 | |
Moodle | >=3.9.0<3.9.7 | |
Moodle | >=3.10.0<3.10.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32475 is classified as a moderate severity vulnerability due to its potential for stored cross-site scripting (XSS) attacks.
To remediate CVE-2021-32475, upgrade your Moodle installation to version 3.10.4, 3.9.7, 3.8.9, or 3.5.18.
Affected versions of Moodle for CVE-2021-32475 include 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, and 3.5 to 3.5.17.
Yes, CVE-2021-32475 poses a risk to all users operating on affected versions of Moodle, particularly those utilizing quiz features.
CVE-2021-32475 is a stored cross-site scripting (XSS) vulnerability affecting the display of ID numbers in quiz grading reports.