GHSA-8g5h-gjwq-w5ch
GitHub Security Advisory
Moodle Logout CSRF in admin/tool/mfa/auth.php
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
The logout option within MFA did not include the necessary token to avoid the risk of users inadvertently being logged out via CSRF.
Affected Packages
Packagist
moodle/moodle
Affected versions:
4.3.0
(fixed in 4.3.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 14, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.