Описание
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-apps/bionic | needs-triage | |
esm-apps/xenial | needs-triage | |
esm-infra/focal | DNE | |
focal | DNE | |
jammy | DNE | |
noble | DNE | |
oracular | DNE | |
plucky | DNE | |
upstream | needs-triage |
Показывать по
10
8.8 High
CVSS3
Связанные уязвимости
CVSS3: 8.8
nvd
около 2 месяцев назад
A flaw was found in Moodle. The analysis request action in the Brickfield tool did not include the necessary token to prevent a Cross-site request forgery (CSRF) risk.
CVSS3: 8.8
debian
около 2 месяцев назад
A flaw was found in Moodle. The analysis request action in the Brickfi ...
github
около 2 месяцев назад
Moodle has a CSRF risk in Brickfield tool's analysis request action
CVSS3: 3.5
fstec
около 2 месяцев назад
Уязвимость компонента Brickfield виртуальной обучающей среды Moodle, позволяющая нарушителю оказать влияние на целостность защищаемой информации
8.8 High
CVSS3