CVE-2021-43558: XSS
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A URL parameter in the filetype site administrator tool required extra sanitizing to prevent a reflected XSS risk.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-43558?
CVE-2021-43558 is a vulnerability in Moodle that allows for a reflected XSS risk.
What are the affected versions of Moodle?
Moodle versions 3.11 to 3.11.3, 3.10 to 3.10.7, and 3.9 to 3.9.10, as well as earlier unsupported versions, are affected by CVE-2021-43558.
What is the severity rating of CVE-2021-43558?
The severity rating of CVE-2021-43558 is medium, with a CVSS score of 6.1.
How can I fix the vulnerability?
To fix the vulnerability, it is recommended to update Moodle to versions 3.11.4, 3.10.8, or 3.9.11, depending on the affected version.
Where can I find more information about CVE-2021-43558?
You can find more information about CVE-2021-43558 in the following references: [Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2021515) and [Moodle forum](https://moodle.org/mod/forum/discuss.php?d=429097).