Cross-Site Request Forgery Vulnerability in Moodle's Feedback Module
CVE-2024-43434
8.1HIGH
What is CVE-2024-43434?
The Moodle Feedback module features a bulk message sending capability within its non-respondents report. An incorrect check for the CSRF token can lead to unauthorized requests being processed, allowing attackers to exploit this vulnerability for malicious activities such as sending unsolicited messages or altering user interactions without consent.
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published