Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Holme

#20120of 53,624
12.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2021-13872
5.4
2021-03-08
Moodle · Moodle · CVE-2021-20280
Name of the Vulnerable Software and Affected Versions: moodle versions prior to 3.10.2 moodle versions prior to 3.9.5 moodle versions prior to 3.8.8 moodle versions prior to 3.5.17 Description: The issue arises from insufficient sanitizing of text-based feedback answers, leading to stored XSS and blind SSRF risks. Recommendations: For versions prior to 3.10.2, update to version 3.10.2 or later. For versions prior to 3.9.5, update to version 3.9.5 or later. For versions prior to 3.8.8, update to version 3.8.8 or later. For versions prior to 3.5.17, update to version 3.5.17 or later.
PT-2021-3685
7.5
2020-10-15
Moodle · Moodle · CVE-2021-36396
**Name of the Vulnerable Software and Affected Versions** Moodle (affected versions not specified) **Description** The issue is related to insufficient redirect handling in Moodle, allowing an attacker to bypass cURL blocked hosts/allowed ports restrictions. This results in a blind Server-Side Request Forgery (SSRF) risk, where an attacker can exploit the vulnerability to perform SSRF attacks. The vulnerability is associated with inadequate input validation. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.