Untriaged
Moodle: csrf risk in feedback non-respondents report
The bulk message sending feature in Moodle's Feedback module's non-respondents report had an incorrect CSRF token check, leading to a CSRF vulnerability.
Affected products
moodle
- <4.2.9
- <4.1.12
- <4.3.6
- <4.4.2
Package maintainers
-
@freezeboy freezeboy
-
@kmein Kierán Meinhardt <kmein@posteo.de>