CVE-2022-2986: CSRF
============================================================================== MSA-22-0022: CSRF risk in enabling/disabling installed H5P libraries
Description: Enabling and disabling installed H5P libraries did not include the necessary token to prevent a CSRF risk. Issue summary: CSRF risk in enabling/disabling installed H5P libraries Severity/Risk: Minor Versions affected: 4.0 to 4.0.2 and 3.11 to 3.11.8 Versions fixed: 4.0.3 and 3.11.9 Reported by: Paul Holden Issue no.: MDL-75326 CVE identifier: Pending Changes (master): http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326
==============================================================================
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-2986?
CVE-2022-2986 is a vulnerability that allows attackers to perform Cross-Site Request Forgery (CSRF) attacks by enabling or disabling installed H5P libraries without the necessary token.
Which software is affected by CVE-2022-2986?
Moodle versions between 3.11.0 and 3.11.9, and Moodle versions between 4.0.0 and 4.0.3 are affected by CVE-2022-2986.
What is the severity of CVE-2022-2986?
CVE-2022-2986 has a severity value of 8.8, which is considered high.
How can I fix CVE-2022-2986?
To fix CVE-2022-2986, upgrade your Moodle installation to version 3.11.9 or higher for versions 3.11.x, and version 4.0.3 or higher for versions 4.0.x.
Where can I find more information about CVE-2022-2986?
You can find more information about CVE-2022-2986 in the following references: [Git commit](http://git.moodle.org/gw?p=moodle.git&a=search&h=HEAD&st=commit&s=MDL-75326), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=2121360), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi/show_bug.cgi?id=2122182).