Описание
Moodle Cross-Site Request Forgery (CSRF)
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
Пакеты
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 3.11, < 3.11.9
3.11.9
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 4.0, < 4.0.3
4.0.3
Связанные уязвимости
CVSS3: 8.8
ubuntu
около 3 лет назад
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CVSS3: 8.8
nvd
около 3 лет назад
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CVSS3: 8.8
debian
около 3 лет назад
Enabling and disabling installed H5P libraries did not include the nec ...