CVE-2021-20185 describes a denial-of-service vulnerability in Moodle versions prior to 3.10.1, 3.9.4, 3.8.7, and 3.5.16. The flaw allowed users to send messages without character limits, potentially causing client-side browser denial of service for recipients of excessively large messages. Rated with a CVSS score of 5.3 (Medium), this vulnerability has a low attack complexity and does not require user interaction or privileges, but its impact is limited to availability. The FAUCET Risk Score is 20/100, indicating a relatively low overall risk. There is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness or concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.5.0, < 3.5.16CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.8.0, < 3.8.7CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.4CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
3.10.0CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:3.10.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.