VDB
Sign up
LOW3.1

GHSA-9vc3-vm42-fjhm

Moodle's mod_data edit/delete pages pass CSRF token in GET parameter

Quick fix

GHSA-9vc3-vm42-fjhm — moodle/moodle: upgrade to the fixed version with the command below.

composer require moodle/moodle:^4.3.12

Details

A security vulnerability was found in Moodle where confidential information that prevents cross-site request forgery (CSRF) attacks was shared publicly through the site's URL. This vulnerability occurred specifically on two types of pages within the mod_data module: edit and delete pages.

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/moodle/moodle
Introduced in: 0Fixed in: 4.3.12
Fixcomposer require moodle/moodle:^4.3.12
Packagist/moodle/moodle
Introduced in: 4.3.0-betaFixed in: 4.3.12
Fixcomposer require moodle/moodle:^4.3.12
Packagist/moodle/moodle
Introduced in: 4.4.0-betaFixed in: 4.4.8
Fixcomposer require moodle/moodle:^4.4.8
Packagist/moodle/moodle
Introduced in: 4.5.0-betaFixed in: 4.5.4
Fixcomposer require moodle/moodle:^4.5.4

References