PT-2021-19681 · Moodle+1 · Moodle+1

Published

2021-05-10

·

Updated

2024-03-06

·

CVE-2021-32244

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Moodle version 3.10.3
Description: The issue allows remote attackers to execute arbitrary web script or HTML via the Description field, which is a Cross Site Scripting (XSS) issue.
Recommendations: For Moodle version 3.10.3, update to a newer version that contains a fix for this issue.

Exploit

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1777
BIT-MOODLE-2021-32244
CVE-2021-32244
GHSA-G5M5-J48G-FR24

Affected Products

Alt Linux
Moodle