CVE-2021-43559
published 2021-11-22CVE-2021-43559: A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality…
PriorityP342high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
0.61%
45.6th percentile
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fedoraproject | extra_packages_for_enterprise_linux | — | — |
| fedoraproject | fedora | — | — |
| moodle | moodle | <= 3.8.8 | — |
| moodle | moodle | — | — |
| moodle | moodle | >= 3.10 < 3.10.8 | 3.10.8 |
| moodle | moodle | >= 3.10.0 < 3.10.8 | 3.10.8 |
| moodle | moodle | >= 3.11 < 3.11.4 | 3.11.4 |
| moodle | moodle | >= 3.11.0 < 3.11.4 | 3.11.4 |
| moodle | moodle | >= 3.9 < 3.9.11 | 3.9.11 |
| moodle | moodle | >= 3.9.0 < 3.9.11 | 3.9.11 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Moodle contains CSRF vulnerability
ghsa·2022-05-24
CVE-2021-43559 [HIGH] CWE-352 Moodle contains CSRF vulnerability
Moodle contains CSRF vulnerability
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
OSV
Moodle contains CSRF vulnerability
osv·2022-05-24
CVE-2021-43559 [HIGH] Moodle contains CSRF vulnerability
Moodle contains CSRF vulnerability
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
OSV
CVE-2021-43559: A flaw was found in Moodle in versions 3
osv·2021-11-22·CVSS 8.8
CVE-2021-43559 [HIGH] CVE-2021-43559: A flaw was found in Moodle in versions 3
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-11-22
Published