CVE-2021-43559
—CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
Description
A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.
- Vendors
- moodlefedoraproject
- Products
- moodle, extra packages for enterprise linux, fedora
- Weakness
- CWE-352
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.