Cross-Site Request Forgery Risk in H5P Libraries of Moodle by Moodle
CVE-2022-2986
8.8HIGH
What is CVE-2022-2986?
A vulnerability has been identified in Moodle's H5P libraries where enabling and disabling features lacked the necessary security token, leaving it susceptible to Cross-Site Request Forgery (CSRF) attacks. An attacker could exploit this weakness to perform unauthorized actions on behalf of a legitimate user, potentially compromising the integrity of the application.
Affected Version(s)
moodle moodle 4.0.3 and moodle 3.11.9