The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
2024-11-07T14:15:16.067
2025-05-01T16:03:08.523
Analyzed
CVSSv3.1: 8.1 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | moodle | moodle | < 4.1.12 | Yes |
Application | moodle | moodle | < 4.2.9 | Yes |
Application | moodle | moodle | < 4.3.6 | Yes |
Application | moodle | moodle | < 4.4.2 | Yes |