vulnerability
Moodle: Cross-Site Request Forgery (CSRF) (CVE-2022-0335)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:N/AC:M/Au:N/C:P/I:P/A:P) | Jan 25, 2022 | Feb 3, 2022 | Feb 3, 2022 |
Severity
7
CVSS
(AV:N/AC:M/Au:N/C:P/I:P/A:P)
Published
Jan 25, 2022
Added
Feb 3, 2022
Modified
Feb 3, 2022
Description
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.
Solution(s)
moodle-upgrade-3_10_9moodle-upgrade-3_11_5moodle-upgrade-3_9_12

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.