Cross-Site Request Forgery Risk in Moodle Database Templates
CVE-2023-28335
8.8HIGH
What is CVE-2023-28335?
A vulnerability has been identified in the Moodle platform, where the link to reset all templates of a database activity fails to include the required CSRF token. This oversight creates a risk of unauthorized actions being performed on behalf of logged-in users, potentially leading to data manipulation or disclosure. It is crucial for users to apply the latest updates to mitigate this security threat.
Affected Version(s)
moodle 4.1 to 4.1.1