First published: Fri Jan 21 2022(Updated: )
A flaw was found in Moodle in versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11 and earlier unsupported versions. The "delete badge alignment" functionality did not include the necessary token check to prevent a CSRF risk.
Credit: patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
composer/moodle/moodle | >=3.9<3.9.11 | 3.9.11 |
composer/moodle/moodle | >=3.10<3.10.8 | 3.10.8 |
composer/moodle/moodle | >=3.11<3.11.5 | 3.11.5 |
redhat/moodle | <3.11.5 | 3.11.5 |
redhat/moodle 3.10.9 and moodle | <3.9.12 | 3.9.12 |
Moodle | <=3.8.9 | |
Moodle | >=3.9.0<3.9.12 | |
Moodle | >=3.10.0<3.10.9 | |
Moodle | >=3.11.0<3.11.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-0335 is classified as a moderate severity vulnerability due to its impact on security through CSRF risk.
To fix CVE-2022-0335, upgrade Moodle to version 3.11.5 or later, 3.10.9 or later, or 3.9.12 or later.
CVE-2022-0335 affects Moodle versions 3.11 to 3.11.4, 3.10 to 3.10.8, 3.9 to 3.9.11, and earlier unsupported versions.
CVE-2022-0335 is a Cross-Site Request Forgery (CSRF) vulnerability that arises from missing token checks.
CVE-2022-0335 impacts the "delete badge alignment" functionality within Moodle.