CVE-2021-43559 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Moodle versions 3.11 to 3.11.3, 3.10 to 3.10.7, and 3.9 to 3.9.10, as well as earlier unsupported versions. The flaw specifically resides in the "delete related badge" functionality, which lacked a necessary token check. This vulnerability carries a high CVSS score of 8.8, indicating a critical risk. It can be exploited remotely with low attack complexity, requiring user interaction, and could lead to high impacts on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, and no public exploit code is available on platforms like Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.8.8CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.9.0, < 3.9.11CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.10.0, < 3.10.8CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
>= 3.11.0, < 3.11.4CPE matchmatch criteria | cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:* | ||
7.0CPE matchmatch criteria | cpe:2.3:a:fedoraproject:extra_packages_for_enterprise_linux:7.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.