Cross-Site Request Forgery Vulnerability in Moodle by Moodle
CVE-2018-16854

6.5MEDIUM

Key Information:

Vendor

[unknown]

Status
Vendor
CVE Published:
26 November 2018

Badges

👾 Exploit Exists

What is CVE-2018-16854?

A vulnerability exists in various versions of Moodle, where the login form lacks a proper token to prevent cross-site request forgery (CSRF) attacks. This oversight allows malicious actors to exploit the login functionality, potentially gaining unauthorized access to users' accounts. The issue affects multiple versions, including 3.5 up to 3.5.2, 3.4 up to 3.4.5, 3.3 up to 3.3.8, and 3.1 up to 3.1.14. Users are encouraged to upgrade to the latest versions—3.6, 3.5.3, 3.4.6, 3.3.9, and 3.1.15—where this flaw has been addressed and a secure login process has been re-established.

Affected Version(s)

moodle 3.6

moodle 3.5.3

moodle 3.4.6

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.