ZeroHour

CVE-2021-32478

CVSS 3.1
6.1 medium
EPSS
1%p64
Published
()
Modified
Description

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

Vendors
moodle
Products
moodle
Weakness
CWE-79, CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.