CVE-2021-40692: Medium severity moodle vulnerability
Published Jan 21, 2022
·Updated
Insufficient capability checks made it possible for teachers to download users outside of their courses.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle>=3.9<3.9.10
3.9.10
composer/moodle/moodle>=3.10<3.10.7
3.10.7
composer/moodle/moodle>=3.11<3.11.3
3.11.3
Moodle moodle>=3.9.0<3.9.10
Moodle moodle>=3.10.0<3.10.7
Moodle moodle>=3.11.0<3.11.3
Event History
Jan 21, 2022
Data Sourced
via Red Hat·08:36 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·06:17 PM
Data Sourced
via MITRE·06:17 PM
DescriptionWeakness
Sep 30, 2022
Advisory Published
via GitHub·12:00 AM
Frequently Asked Questions
1
What is CVE-2021-40692?
CVE-2021-40692 is a vulnerability that allows teachers to download users outside of their courses in Moodle.
2
What is the severity of CVE-2021-40692?
CVE-2021-40692 has a severity rating of medium (4.3).
3
How does CVE-2021-40692 affect Moodle?
CVE-2021-40692 affects Moodle versions 3.9.0 to 3.9.10, 3.10.0 to 3.10.7, and 3.11.0 to 3.11.3.
4
How can the CVE-2021-40692 vulnerability be exploited?
The CVE-2021-40692 vulnerability can be exploited by teachers to download users outside of their assigned courses.
5
Is there a fix for CVE-2021-40692?
Yes, updating Moodle to version 3.9.10, 3.10.7, or 3.11.3 will fix the CVE-2021-40692 vulnerability.