PT-2023-12115 · Moodle+1 · Moodle+1

Published

2021-03-08

·

Updated

2024-10-20

·

CVE-2021-27131

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Moodle versions prior to 3.1.2 Moodle version 3.10.1
Description The issue is related to persistent/stored cross-site scripting (XSS) due to improper input sanitization on the Additional HTML Section via Header and Footer parameter in "/admin/settings.php". This could allow an attacker to steal admin and all user account cookies by storing a malicious XSS payload in Header and Footer.
Recommendations For Moodle versions prior to 3.1.2: Update to the latest version to mitigate cross-site scripting risks. For Moodle version 3.10.1: Update to the latest version to mitigate risks. As a temporary workaround, consider restricting access to the Header and Footer parameter in "/admin/settings.php" to minimize the risk of exploitation.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

ALT-PU-2021-1445
ALT-PU-2021-1497
ALT-PU-2022-1641
BIT-MOODLE-2021-27131
CVE-2021-27131
GHSA-W2PM-FR62-JGV4

Affected Products

Alt Linux
Moodle