← back
CVE-2021-21809high

CVE-2021-21809

41Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 8.2epss 24%
from disclosure to weapon0 days
Published on NVDJun 23
metasploitJun 22
exploitation probability
24%top 2% of all CVEs
observed exploitation
nono source reports it
A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:L
Affected products
n/a · Moodle