REDHAT-BUG-2543643: CSRF
A flaw was found in Moodle. The XML grade import functionality, which allows setting or overwriting of student grades, did not include the token required to prevent a cross-site request forgery (CSRF) risk, allowing an attacker to overwrite grades on behalf of a logged-in victim who visits a malicious page.
Affected Software
Event History
Frequently Asked Questions
Who could be affected by this issue?
Logged-in Moodle users who can use the XML grade import functionality may be exposed if they visit a malicious page. The attacker could cause grade changes to be submitted using that victim's authenticated session.
What does an attacker need to exploit the flaw?
An attacker needs to induce a logged-in victim to visit a malicious page. The described attack relies on the victim's existing authenticated Moodle session and the missing CSRF token on XML grade import requests.
What is the impact of a successful exploit?
A successful attack can set or overwrite student grades through the XML grade import functionality on behalf of the logged-in victim.