Описание
Moodle Cross-Site Request Forgery (CSRF)
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
Пакеты
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 3.11, < 3.11.9
3.11.9
Наименование
moodle/moodle
composer
Затронутые версииВерсия исправления
>= 4.0, < 4.0.3
4.0.3
Связанные уязвимости
CVSS3: 8.8
ubuntu
больше 2 лет назад
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CVSS3: 8.8
nvd
больше 2 лет назад
Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk.
CVSS3: 8.8
debian
больше 2 лет назад
Enabling and disabling installed H5P libraries did not include the nec ...