PT-2021-14791 · Moodle+1 · Moodle+1

Adam Reiser

·

Published

2021-01-17

·

Updated

2024-03-06

·

CVE-2021-21809

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Moodle version 3.10
Description A command execution vulnerability exists in the default legacy spellchecker plugin. This issue can be exploited through a specially crafted series of HTTP requests, leading to command execution. An attacker must have administrator privileges to exploit this vulnerability.
Recommendations For Moodle version 3.10, consider disabling the default legacy spellchecker plugin until a patch is available to prevent command execution. Restrict access to administrator privileges to minimize the risk of exploitation.

Exploit

Fix

Incorrect Permission

OS Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1050
ALT-PU-2021-1098
BIT-MOODLE-2021-21809
CVE-2021-21809
GHSA-C7JJ-VFMR-J9MJ

Affected Products

Alt Linux
Moodle