First published: Fri Mar 17 2023(Updated: )
The link to reset all templates of a database activity did not include the necessary token to prevent a CSRF risk.
Credit: patrick@puiterwijk.org patrick@puiterwijk.org
Affected Software | Affected Version | How to fix |
---|---|---|
Moodle Moodle | =4.1.0 | |
Moodle Moodle | =4.1.1 | |
redhat/moodle | <4.1.2 | 4.1.2 |
composer/moodle/moodle | >=4.1.0<4.1.2 | 4.1.2 |
=4.1.0 | ||
=4.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-28335 is a vulnerability in Moodle 4.1.0 and 4.1.1 that allows CSRF attacks through a link to reset all templates of a database activity.
The severity of CVE-2023-28335 is high with a CVSS score of 8.8.
CVE-2023-28335 affects Moodle versions 4.1.0 and 4.1.1.
To fix CVE-2023-28335, update your Moodle installation to version 4.1.2 or higher.
You can find more information about CVE-2023-28335 on the Moodle forum: [link](https://moodle.org/mod/forum/discuss.php?d=445067)