Vulnerability Description
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Moodle | Moodle | >= 3.9.0, <= 3.9.10 |
Related Weaknesses (CWE)
References
- https://bugzilla.redhat.com/show_bug.cgi?id=2021963Issue TrackingThird Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=429095PatchVendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2021963Issue TrackingThird Party Advisory
- https://moodle.org/mod/forum/discuss.php?d=429095PatchVendor Advisory
FAQ
What is CVE-2021-3943?
CVE-2021-3943 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. A remote code execution risk when restoring backup files was identified.
How severe is CVE-2021-3943?
CVE-2021-3943 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-3943?
Check the references section above for vendor advisories and patch information. Affected products include: Moodle Moodle.