vulnerability
Moodle: Cross-Site Request Forgery (CSRF) (CVE-2024-38276)
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
9 | (AV:N/AC:M/Au:N/C:C/I:C/A:C) | 06/18/2024 | 08/12/2024 | 01/28/2025 |
Severity
9
CVSS
(AV:N/AC:M/Au:N/C:C/I:C/A:C)
Published
06/18/2024
Added
08/12/2024
Modified
01/28/2025
Description
Incorrect CSRF token checks resulted in multiple CSRF risks.
Solution(s)
moodle-upgrade-4_1_10moodle-upgrade-4_2_8moodle-upgrade-4_3_5
References
- CVE-2024-38276
- https://attackerkb.com/topics/CVE-2024-38276
- URL-https://lists.fedoraproject.org/archives/list/[email protected]/message/F7AZYR7EXV6E5SQE2GYTNQE3NOENJCQ6/
- URL-https://lists.fedoraproject.org/archives/list/[email protected]/message/GHTIX55J4Q4LEOMLNEA4OZSWVEENQX7E/
- URL-https://moodle.org/mod/forum/discuss.php?d=459501

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.