ZeroHour

CVE-2021-43559

CVSS 3.1
8.8 high
EPSS
<1%p47
Published
()
Modified
Description

A flaw was found in Moodle in versions 3.11 to 3.11.3, 3.10 to 3.10.7, 3.9 to 3.9.10 and earlier unsupported versions. The "delete related badge" functionality did not include the necessary token check to prevent a CSRF risk.

Vendors
moodlefedoraproject
Products
moodle, extra packages for enterprise linux, fedora
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.