Multiple CSRF Risks Due to Incorrect Token Checks
CVE-2024-38276
8.8HIGH
Summary
The vulnerability arises from improper checks on CSRF tokens, which can expose vulnerable instances of Moodle to multiple cross-site request forgery (CSRF) attacks. Exploiting this flaw may allow attackers to perform unauthorized actions on behalf of users. It is essential for administrators to review their Moodle installation and implement security best practices to mitigate risks and protect user data. Regularly updating to the latest versions and monitoring official security announcements are recommended to safeguard against such vulnerabilities.
Affected Version(s)
Moodle 4.4
Moodle 4.3 <= 4.3.4
Moodle 4.2 <= 4.2.7
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved