CVE-2024-34001: moodle: CSRF risk in admin preset tool management of presets
Published May 31, 2024
·Updated
Actions in the admin preset tool did not include the necessary token to prevent a CSRF risk.
Affected Software
6 affected componentsFixes available
composer/moodle/moodle<4.1.10
4.1.10
composer/moodle/moodle>=4.2.0<4.2.7
4.2.7
composer/moodle/moodle>=4.3.0<4.3.4
4.3.4
Moodle moodle<4.1.10
Moodle moodle>=4.2.0<4.2.7
Moodle moodle>=4.3.0<4.3.4
Event History
May 31, 2024
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
Affected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-34001?
CVE-2024-34001 is a medium severity vulnerability due to its CSRF risk in the admin preset tool.
2
How do I fix CVE-2024-34001?
To fix CVE-2024-34001, upgrade to Moodle version 4.1.10, 4.2.7, or 4.3.4.
3
What types of attacks does CVE-2024-34001 expose systems to?
CVE-2024-34001 exposes systems to Cross-Site Request Forgery (CSRF) attacks.
4
Which versions of Moodle are affected by CVE-2024-34001?
CVE-2024-34001 affects Moodle versions prior to 4.1.10 and between 4.2.0 to 4.2.7, as well as versions between 4.3.0 to 4.3.4.
5
Is there a patch available for CVE-2024-34001?
Yes, a patch is available by upgrading to the specified remedial versions of Moodle.