4.3 MEDIUM
- CVSS version: 3.1
- Attack vector (AV): NETWORK
- Attack complexity (AC): LOW
- Privileges required (PR): NONE
- User interaction (UI): REQUIRED
- Scope (S): UNCHANGED
- Confidentiality impact (C): LOW
- Integrity impact (I): NONE
- Availability impact (A): NONE
Msa-24-0005: csrf risk in language import utility
The link to update all installed language packs did not include the necessary token to prevent a CSRF risk.
References
-
-
-
https://moodle.org/mod/forum/discuss.php?d=455638 x_transferred
-
-
-
-
-
-
-
https://moodle.org/mod/forum/discuss.php?d=455638 x_transferred
-
-
-
https://moodle.org/mod/forum/discuss.php?d=455638 x_transferred
Affected products
- ==and 4.1.9
- <4.3.3
- <4.1.9
- <4.2.6
- ==4.3.3
Matching in nixpkgs
pkgs.moodle
Free and open-source learning management system (LMS) written in PHP
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>