← Back to browse · API

CVE-2021-21809

Severity
HIGH
CVSS
8.2
EPSS
0.24173
Risk score
41.26
CISA KEV
No
PoC
No
Published
2021-06-23
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2022-3528, GHSA-C7JJ-VFMR-J9MJ
Products
Moodle:Moodle Moodle 3.10
Sources
euvd EUVD-2022-3528

Description

A command execution vulnerability exists in the default legacy spellchecker plugin in Moodle 3.10. A specially crafted series of HTTP requests can lead to command execution. An attacker must have administrator privileges to exploit this vulnerabilities.

References