Vulnerability Description
An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | < 3.5.18 |
Related Weaknesses (CWE)
References
- https://moodle.org/mod/forum/discuss.php?d=422308PatchVendor Advisory
- https://moodle.org/mod/forum/discuss.php?d=422308PatchVendor Advisory
FAQ
What is CVE-2021-32474?
CVE-2021-32474 is a vulnerability with a CVSS score of 7.2 (HIGH). An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. M...
How severe is CVE-2021-32474?
CVE-2021-32474 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-32474?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.