vulnerability

Moodle: Cross-Site Request Forgery (CSRF) (CVE-2022-0335)

Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jan 25, 2022
Added
Feb 3, 2022
Modified
Feb 3, 2022

Description

A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.

Solution(s)

moodle-upgrade-3_10_9moodle-upgrade-3_11_5moodle-upgrade-3_9_12
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.