Vulnerability Name: | CVE-2021-32474 (CCN-221920) |
Assigned: | 2021-05-17 |
Published: | 2021-05-17 |
Updated: | 2022-03-18 |
Summary: | An SQL injection risk existed on sites with MNet enabled and configured, via an XML-RPC call from the connected peer host. Note that this required site administrator access or access to the keypair. Moodle 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8, 3.5 to 3.5.17 and earlier unsupported versions are affected.
|
CVSS v3 Severity: | 7.2 High (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H) 6.9 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): High User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): High Integrity (I): High Availibility (A): High | 5.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N) 5.2 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:H/RL:O/RC:C)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): Low User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): Low Integrity (I): Low Availibility (A): None |
|
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): Single_Instance | Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): Partial | 5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): Single_Instance
| Impact Metrics: | Confidentiality (C): Partial Integrity (I): Partial Availibility (A): None |
|
Vulnerability Type: | CWE-89
|
Vulnerability Consequences: | Data Manipulation |
References: | Source: MITRE Type: CNA CVE-2021-32474
Source: XF Type: UNKNOWN moodle-cve202132474-sql-injection(221920)
Source: CCN Type: Moodle Security Advisory MSA-21-0014 Blind SQL injection possible via MNet authentication
|
Vulnerable Configuration: | Configuration CCN 1: cpe:/a:moodle:moodle:3.5.0:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.10:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.10.3:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.9.6:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.8.8:*:*:*:*:*:*:*OR cpe:/a:moodle:moodle:3.5.17:*:*:*:*:*:*:*
Denotes that component is vulnerable |
BACK |