Record summary

CVE-2021-32478 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The redirect URI in the LTI authorization endpoint required extra sanitizing to prevent reflected XSS and open redirect risks. Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 and earlier unsupported versions are affected.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Nov 5, 2025 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

Affected products and versions

3
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied

moodle

CVE List3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8affected
GitHub Advisory3.10 to < 3.10.4 · Fixed in 3.10.4affected
3.9 to < 3.9.7 · Fixed in 3.9.7affected
3.8 to < 3.8.9 · Fixed in 3.8.9affected

Nuclei templates

1
ProjectDiscoveryMEDIUMMoodle 3.8-3.10.3 - Reflected XSS & Open RedirectCVSS 6.1

Moodle versions 3.10 to 3.10.3, 3.9 to 3.9.6, 3.8 to 3.8.8 contain a reflected XSS and open redirect caused by insufficient sanitization of the redirect URI in the LTI authorization endpoint, letting attackers execute scripts or redirect users maliciously, exploit requires crafted URL with malicious redirect URI.

Impact

Attackers can inject malicious JavaScript or redirect users to malicious sites via insufficient sanitization in the redirect_uri parameter.

Remediation

Upgrade to Moodle version 3.8.9, 3.9.7, or 3.10.4 or later.

WeaknessesCWE-79
Authorshackergautam
Template tagscvecve2021moodlexssintrusivevulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:moodle:moodle:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3