Lucene search

K
cvelistRedhatCVELIST:CVE-2021-32474
HistoryMar 11, 2022 - 5:54 p.m.

CVE-2021-32474

2022-03-1117:54:25
CWE-89
redhat
www.cve.org
7
sql injection
mnet
xml-rpc
moodle
vulnerability
cve-2021-32474

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

37.0%

An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

CNA Affected

[
  {
    "product": "moodle",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17"
      }
    ]
  }
]

AI Score

7.6

Confidence

High

EPSS

0.001

Percentile

37.0%