CVE-2021-32478: XSS
Published Mar 11, 2022
·Updated
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
Affected Software
3 affected components
Moodle moodle<3.8.9
Moodle moodle>=3.9.0<3.9.7
Moodle moodle>=3.10.0<3.10.4
Remediation
Patch Available
Event History
Mar 11, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-32478?
The severity of CVE-2021-32478 is medium with a severity value of 6.1.
2
What is the affected software for CVE-2021-32478?
The affected software for CVE-2021-32478 is Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions.
3
What are the risks associated with CVE-2021-32478?
CVE-2021-32478 poses risks of reflected XSS and open redirect.
4
How can I fix CVE-2021-32478?
To fix CVE-2021-32478, upgrade to Moodle versions 3.10.4, 3.9.7, or 3.8.9 or apply the necessary patches provided by Moodle.
5
Where can I find more information about CVE-2021-32478?
You can find more information about CVE-2021-32478 at: https://moodle.org/mod/forum/discuss.php?d=422314