VDB

CVE-2021-32474

CVE-2021-32474 PUBLISHED CVSS 7.199999809265137 HIGH

An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.

EPSS 0.93% · 59.1th percentile

Risk Scores

CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.93%
59.1th percentile

Affected Products

VendorProductVersions
Bitnamimoodle3.10.0, 0, 3.8.0
Bitnamimoodle0, 3.9.0, 3.10.0

Timeline

  • May 17, 2021 CVE Published
  • Mar 12, 2022 EPSS Score
  • May 3, 2022 EPSS Score
  • Jun 24, 2022 EPSS Score
  • Oct 7, 2022 EPSS Score
  • Nov 28, 2022 EPSS Score
  • Jan 19, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 12, 2023 EPSS Score
  • Jun 23, 2023 EPSS Score
  • Aug 14, 2023 EPSS Score
  • Oct 5, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›