Описание
Moodle has a CSRF risk in user tours manager that allows tour duplication
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
Пакеты
moodle/moodle
< 4.1.18
4.1.18
moodle/moodle
>= 4.3.0-beta, < 4.3.12
4.3.12
moodle/moodle
>= 4.4.0-beta, < 4.4.8
4.4.8
moodle/moodle
>= 4.5.0-beta, < 4.5.4
4.5.4
Связанные уязвимости
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
A security vulnerability was discovered in Moodle that allows anyone t ...
Уязвимость виртуальной обучающей среды Moodle, связанная с подделкой межсайтовых запросов, позволяющая нарушителю оказать влияние на целостность защищаемой информации