CVE-2021-3943: Input Validation
Published Nov 10, 2021
·Updated
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
Affected Software
5 affected componentsFixes available
redhat/moodle<3.11.4
3.11.4
redhat/moodle 3.10.8 and moodle<3.9.11
3.9.11
Moodle moodle>=3.9.0<=3.9.10
Moodle moodle>=3.10.0<=3.10.7
Moodle moodle>=3.11.0<=3.11.3
Remediation
Patch Available
Event History
Nov 10, 2021
Data Sourced
via Red Hat·01:30 PM
DescriptionSeverityAffected Software
Nov 22, 2021
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-3943?
CVE-2021-3943 has a critical severity rating due to its potential for remote code execution.
2
How do I fix CVE-2021-3943?
To fix CVE-2021-3943, upgrade Moodle to version 3.11.4 or later, or to 3.9.11.
3
Which versions of Moodle are affected by CVE-2021-3943?
CVE-2021-3943 affects Moodle versions 3.11 to 3.11.3, 3.10 to 3.10.7, and 3.9 to 3.9.10.
4
What vulnerability does CVE-2021-3943 address?
CVE-2021-3943 addresses a remote code execution risk when restoring backup files in Moodle.
5
How can I determine if my Moodle installation is vulnerable to CVE-2021-3943?
Check the installed version of Moodle against the affected versions listed for CVE-2021-3943 to determine vulnerability.