Vulnerability Name: | CVE-2021-20186 (CCN-195789) |
Assigned: | 2020-12-17 |
Published: | 2021-01-25 |
Updated: | 2021-02-01 |
Summary: | It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that if the TeX notation filter was enabled, additional sanitizing of TeX content was required to prevent the risk of stored XSS.
|
CVSS v3 Severity: | 5.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N) 5.2 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): Required | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None | 7.2 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N) 6.9 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Changed
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 2.1 Low (CVSS v2 Vector: AV:N/AC:H/Au:S/C:P/I:N/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): High Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): None Availibility (A): None | 6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-79
|
Vulnerability Consequences: | Cross-Site Scripting |
References: | Source: MITRE Type: CNA CVE-2021-20186
Source: XF Type: UNKNOWN moodle-cve202120186-xss(195789)
Source: CCN Type: Moodle Security Advisory MSA-21-0004 Stored XSS possible via TeX notation filter
Source: MISC Type: Patch, Vendor Advisory https://moodle.org/mod/forum/discuss.php?d=417170
Source: CCN Type: WhiteSource Vulnerability Database CVE-2021-20186
|
Vulnerable Configuration: | Configuration 1: cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version < 3.5.16)OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version >= 3.8.0 and < 3.8.7)OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version >= 3.9.0 and < 3.9.4)OR cpe:/a:moodle:moodle:*:*:*:*:*:*:*:* (Version >= 3.10.0 and < 3.10.1) Configuration CCN 1: cpe:/a:moodle:moodle:3.5.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.9.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.8.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.5.15:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |