← back
CVE-2021-32478observed exploitationCWE-79

CVE-2021-32478

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 1.1%
from disclosure to weapon
Published on NVDMar 11
VulnCheck+1335d
exploitation probability
1.1%top 36% of all CVEs
observed exploitation
yesVulnCheck
The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.
Affected products
n/a · moodle