First published: Wed Nov 10 2021(Updated: )
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/moodle | <3.11.4 | 3.11.4 |
redhat/moodle 3.10.8 and moodle | <3.9.11 | 3.9.11 |
Moodle | >=3.9.0<=3.9.10 | |
Moodle | >=3.10.0<=3.10.7 | |
Moodle | >=3.11.0<=3.11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3943 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2021-3943, upgrade Moodle to version 3.11.4 or later, or to 3.9.11.
CVE-2021-3943 affects Moodle versions 3.11 to 3.11.3, 3.10 to 3.10.7, and 3.9 to 3.9.10.
CVE-2021-3943 addresses a remote code execution risk when restoring backup files in Moodle.
Check the installed version of Moodle against the affected versions listed for CVE-2021-3943 to determine vulnerability.