CVE-2021-36396 is a server-side request forgery vulnerability in Moodle caused by insufficient handling of HTTP redirects in cURL-based outbound requests. The flaw allows an attacker to blindly bypass configured cURL blocked-host and allowed-port restrictions by leveraging redirect behavior, causing the Moodle server to issue unintended outbound requests to destinations that should otherwise be restricted. Based on the provided information, the issue is specifically characterized as a blind SSRF condition rather than one that directly exposes response content to the attacker.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a Python proof-of-concept exploit for CVE-2021-36393, a critical SQL injection vulnerability in Moodle's 'recent courses' feature. The exploit targets the 'sort' parameter in a JSON POST request to the core_course_get_enrolled_courses_by_timeline_classification endpoint. By leveraging time-based blind SQL injection (using SLEEP(3)), the script extracts the database name, the username, and the password hash of the first user in the Moodle database. The exploit requires a valid session (student or higher) and is configured to target a local Moodle instance by default, but can be adapted for remote targets. The repository consists of a README.md with usage instructions and vulnerability details, a requirements.txt listing Python dependencies (requests, termcolor), and the main exploit script (exploit.py). No hardcoded remote endpoints are present; the default target is localhost, but this can be changed as needed.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.