ZeroHour

CVE-2024-34007

CVSS 3.1
8.8 high
EPSS
<1%p28
Published
()
Modified
Description

The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.

Vendors
moodle
Products
moodle
Weakness
CWE-352
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.