Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpfv-89vg-r562

Опубликовано: 28 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Cross Site Request Forgery in Moodle

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

Пакеты

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.11, < 3.11.5

3.11.5

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.10, < 3.10.8

3.10.8

Наименование

moodle/moodle

composer
Затронутые версииВерсия исправления

>= 3.9, < 3.9.11

3.9.11

EPSS

Процентиль: 39%
0.00172
Низкий

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 8.8
ubuntu
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
nvd
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

CVSS3: 8.8
debian
больше 3 лет назад

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, ...

EPSS

Процентиль: 39%
0.00172
Низкий

8.8 High

CVSS3

Дефекты

CWE-352