CSRF Token Vulnerability in Moodle by Moodle
CVE-2019-10186
What is CVE-2019-10186?
A security flaw was identified in Moodle's handling of the XML loading and unloading admin tool. Specifically, prior to version 3.7.1, the application did not properly utilize a sesskey (CSRF) token, potentially allowing an attacker to perform unauthorized actions by exploiting this oversight. This could lead to various security risks, as it bypasses vital security mechanisms designed to protect against CSRF attacks. It is crucial for users to update their Moodle installations to the latest versions to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
moodle 3.7.1
moodle 3.6.5
moodle 3.5.7
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
