CVE-2024-34008: moodle: CSRF risk in analytics management of models
Published May 31, 2024
·Updated
Actions in the admin management of analytics models did not include the necessary token to prevent a CSRF risk.
Affected Software
6 affected componentsFixes available
Moodle moodle>=4.0<4.3.4
Moodle moodle>=4.1<4.1.10
Moodle moodle>=4.2<4.2.7
composer/moodle/moodle<4.1.10
4.1.10
composer/moodle/moodle>=4.2.0<4.2.7
4.2.7
composer/moodle/moodle>=4.3.0<4.3.4
4.3.4
Event History
May 31, 2024
CVE Published
via MITRE·08:44 PM
Data Sourced
via MITRE·08:44 PM
DescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Advisory Published
via GitHub·09:30 PM
Frequently Asked Questions
1
What is the severity of CVE-2024-34008?
CVE-2024-34008 is classified as a medium severity vulnerability due to its potential CSRF risks.
2
How do I fix CVE-2024-34008?
To fix CVE-2024-34008, update Moodle to version 4.1.10, 4.2.7, or 4.3.4 or later.
3
What types of attacks can CVE-2024-34008 lead to?
CVE-2024-34008 can lead to cross-site request forgery (CSRF) attacks, allowing unauthorized actions to be performed on behalf of users.
4
Which versions of Moodle are affected by CVE-2024-34008?
CVE-2024-34008 affects Moodle versions prior to 4.1.10, 4.2.7, and 4.3.4.
5
Is there a patch available for CVE-2024-34008?
Yes, the patch for CVE-2024-34008 is available in the mentioned versions of Moodle.