UBUNTU-CVE-2021-43559

Source
https://ubuntu.com/security/CVE-2021-43559
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-43559.json
JSON Data
https://api.osv.dev/v1/vulns/UBUNTU-CVE-2021-43559
Upstream
Published
2021-11-22T16:15:00Z
Modified
2026-09-23T18:45:39Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

References

Affected packages

Ubuntu:Pro:16.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.7.9+dfsg-1
2.7.10+dfsg-1
2.7.11+dfsg-1
2.7.11+dfsg-2
2.7.12+dfsg-1
3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "moodle",
            "binary_version":  "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-43559.json"

Ubuntu:Pro:18.04:LTS / moodle

Package

Name
moodle
Purl
pkg:deb/ubuntu/moodle?arch=source&distro=esm-apps%2Fbionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.0.3+dfsg-0ubuntu1
3.0.3+dfsg-0ubuntu1+esm1

Ecosystem specific

{
    "binaries":  [
        {
            "binary_name":  "moodle",
            "binary_version":  "3.0.3+dfsg-0ubuntu1+esm1"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2021/UBUNTU-CVE-2021-43559.json"