VDB

CVE-2021-32478

CVE-2021-32478 PUBLISHED

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

EPSS 1.13% · 64.0th percentile

Risk Scores

EPSS Score
1.13%
64.0th percentile

Affected Products

VendorProductVersions
Bitnamimoodle3.9.0, 3.10.0, 0
Bitnamimoodle3.9.0, 3.10.0, 0

Timeline

  • May 17, 2021 CVE Published
  • Jan 16, 2022 CrowdSec Sighting
  • Mar 12, 2022 EPSS Score
  • Sep 27, 2022 CrowdSec Sighting
  • Oct 17, 2022 CrowdSec Sighting
  • Nov 28, 2022 CrowdSec Sighting
  • Dec 11, 2022 CrowdSec Sighting
  • Dec 11, 2022 CrowdSec Sighting
  • Aug 10, 2024 CrowdSec Sighting
  • Aug 19, 2024 CrowdSec Sighting
  • Nov 1, 2024 CrowdSec Sighting
  • Mar 15, 2025 CrowdSec Sighting
Open in Interactive Console →
$ Console Community · 100/wk Open console ›