Home
HIGH: 8.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:NDefault status
unaffected
Any version before 4.1.12
affected
4.2 (semver) before 4.2.9
affected
4.3 (semver) before 4.3.6
affected
4.4 (semver) before 4.4.2
affected
Description
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
Product status
Any version before 4.1.12
4.2 (semver) before 4.2.9
4.3 (semver) before 4.3.6
4.4 (semver) before 4.4.2
Timeline
| 2024-08-12: | Reported to Red Hat. |
| 2024-08-19: | Made public. |
References
bugzilla.redhat.com/show_bug.cgi?id=2304262 (RHBZ#2304262)
moodle.org/mod/forum/discuss.php?d=461203