A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
References
| Link | Resource |
|---|---|
| https://bugzilla.redhat.com/show_bug.cgi?id=2021517 | Issue Tracking Third Party Advisory |
| https://moodle.org/mod/forum/discuss.php?d=429099 | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
|
Information
Published : 2021-11-22 16:15
Updated : 2022-06-14 14:38
NVD link : CVE-2021-43559
Mitre link : CVE-2021-43559
JSON object : View
Products Affected
fedoraproject
- fedora
- extra_packages_for_enterprise_linux
moodle
- moodle
CWE
CWE-352
Cross-Site Request Forgery (CSRF)
