CSRF Vulnerability in Moodle Allows Unauthorised Course Access
A flaw in Moodle was discovered. This happens because Moodle does not properly check where a course redirect URL is coming from. A user's CSRF token was put in the URL when they were redirected to a course they restored. An attacker can fool someone to visit a crafted web page. The attacker can then do things on the website as if they are the user. This issue enables cross-site request forgery attacks.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
moodle moodle |
||
fedoraproject fedora 35 |
||
fedoraproject fedora 36 |
||
fedoraproject fedora 37 |