A security vulnerability was discovered in Moodle that allows anyone to duplicate existing tours without needing to log in due to a lack of protection against cross-site request forgery (CSRF) attacks.
2025-04-25T15:15:37.230
2025-06-24T16:08:36.127
Analyzed
CVSSv3.1: 3.5 (LOW)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | moodle | moodle | < 4.1.18 | Yes |
| Application | moodle | moodle | < 4.3.12 | Yes |
| Application | moodle | moodle | < 4.4.8 | Yes |
| Application | moodle | moodle | < 4.5.4 | Yes |