Lucene search

K
osvGoogleOSV:GHSA-4WVG-7886-83GV
HistoryMay 13, 2022 - 1:12 a.m.

Moodle cross-site request forgery (CSRF) vulnerability

2022-05-1301:12:51
Google
osv.dev
5

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.5%

Cross-site request forgery (CSRF) vulnerability in enrol/imsenterprise/importnow.php in Moodle through 2.3.11, 2.4.x before 2.4.9, 2.5.x before 2.5.5, and 2.6.x before 2.6.2 allows remote attackers to hijack the authentication of administrators for requests that import an IMS Enterprise file.

7.2 High

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

52.5%