VDB
CVE-2021-32474
CVE-2021-32474
PUBLISHED
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
EPSS 1.04% · 77.8th percentile
Risk Scores
EPSS Score
1.04%
77.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bitnami | moodle | 3.10.0, 0, 3.8.0 |
| Bitnami | moodle | 0, 3.9.0, 3.10.0 |
Exploit Intelligence
Timeline
- May 17, 2021 CVE Published
- Mar 12, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jun 23, 2022 EPSS Score
- Oct 4, 2022 EPSS Score
- Nov 25, 2022 EPSS Score
- Jan 15, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 28, 2023 EPSS Score
- Jun 18, 2023 EPSS Score
- Sep 29, 2023 EPSS Score
- Nov 19, 2023 EPSS Score