CVE-2021-36403: Medium severity moodle vulnerability
Published Mar 6, 2023
·Updated
In Moodle, in some circumstances, email notifications of messages could have the link back to the original message hidden by HTML, which may pose a phishing risk.
Affected Software
3 affected components
Moodle moodle<3.9.8
Moodle moodle>=3.10.0<3.10.5
Moodle moodle>=3.11.0<3.11.1
Remediation
Patch Available
Event History
Mar 6, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2021-36403?
CVE-2021-36403 is a vulnerability in Moodle that allows email notifications of messages to have the link back to the original message hidden by HTML, posing a phishing risk.
2
How does CVE-2021-36403 affect Moodle?
CVE-2021-36403 affects Moodle versions 3.9.8, 3.10.0 to 3.10.5, and 3.11.0 to 3.11.1.
3
What is the severity of CVE-2021-36403?
CVE-2021-36403 has a severity rating of medium.
4
What is the Common Weakness Enumeration (CWE) ID for CVE-2021-36403?
The CWE ID for CVE-2021-36403 is 912.
5
How can I mitigate the risk of CVE-2021-36403?
To mitigate the risk of CVE-2021-36403, it is recommended to update Moodle to a version that is not affected by the vulnerability.