Описание
Moodle Logout CSRF in admin/tool/mfa/auth.php
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Пакеты
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 4.3.0, < 4.3.4
4.3.4
Связанные уязвимости
CVSS3: 8.8
ubuntu
около 1 года назад
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVSS3: 8.8
nvd
около 1 года назад
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
CVSS3: 8.8
debian
около 1 года назад
The logout option within MFA did not include the necessary token to av ...